Skip to content

Version 3 - #17293

Merged
Rich-Harris merged 906 commits into
mainfrom
version-3
Oct 1, 2026
Merged

Version 3#17293
Rich-Harris merged 906 commits into
mainfrom
version-3

Conversation

@elliott-with-the-longest-name-on-github

Copy link
Copy Markdown
Contributor

You know what this is for

ottomated and others added 30 commits August 14, 2026 16:41
Ref #15212.

Something we've wanted to do for a while is get rid of the virtual
modules, in favour of writing stuff to disk. The system becomes a lot
easier to understand when it involves real artifacts instead of the
crazy indirection we have going on at the moment.

I started with the `$app/env/*` stuff because that's likely to be the
most challenging, since it involves some mad science around starting up
a mini Vite dev server to load the `src/env.ts` module so that we can
analyse it so that we can create a generated module that _also_ loads
the `src/env.ts` module... anyway, it works, and so I assume we will be
able to do the same for the other `__sveltekit/*` modules.

(We could probably replace the `resolveId` logic with an alias that just
points to the `generated` folder, same as we have for `$app/*`
currently. That can wait for a follow-up PR though.)

Another thing I'm doing in this PR is creating the plugin in a separate
module, rather than adding to the chaos in `vite/index.js`. It involves
a little bit of duplication, but it makes everything so much more
self-contained, and makes the coupling between different plugins more
explicit (e.g. the `callback`).

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <nicolas.polum@outlook.com>
Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
closes #<!-- Add the related issue number here. Repeat this line for
each additional issue it closes -->

<!-- Explain the goal of the PR, why it is needed, and what has been
changed to achieve that goal -->

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [ ] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [ ] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [ ] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [ ] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.
…ercel (#16809)

closes #16806

In a pnpm workspace, `@vercel/nft` can trace the same dependency through
two different symlink chains (e.g. `apps/app/node_modules/X` and
`packages/ui/node_modules/X`) that both realpath to the same file in the
pnpm store. `create_function_bundle` assumed traced file → destination
is 1:1, so the second occurrence hit `fs.symlinkSync` on a `dest` that
already existed and crashed the build with `EEXIST`.

Wraps the symlink in a try/catch that ignores `EEXIST` — both chains
would produce an equivalent link, so skipping the duplicate is safe.
`render_response` types `rendered` with a hand-written `{ head, body,
hashes: { script: string[] } }` and a TODO asking `svelte/server` to
expose `RenderOutput`. The file already imports `render`, so the type is
reachable today, and the hand-written version had drifted from it
(`hashes.script` is `` `sha256-${string}`[] ``).

`Omit` because `SyncRenderOutput` still carries the deprecated `html`,
which neither assignment site sets.

---------

Co-authored-by: Rich Harris <rich.harris@vercel.com>
)

With #16794, `setResponse` derives `content-length` from fixed bodies,
so runtime responses no longer need the `json` helper to be served
correctly on Node. This switches the runtime's `json` call sites to the
native `Response.json` (deprecated by #15448). `text` call sites stay:
`new Response` with a string body adds a default `text/plain`
content-type where the helper adds none, so replacing those changes
response headers and is a separate decision. Tracing is unaffected,
since page and error documents still go through `text`.

Stacked on #16794; retarget to `version-3` once it merges.

---------

Co-authored-by: Rich Harris <richard.a.harris@gmail.com>
…anonical form (#16339)

closes #14781

During SSR, fetch responses are embedded as `<script
data-sveltekit-fetched data-url=...>` tags, and during hydration the
client rebuilds the url to find them instead of hitting the network. The
two sides build it differently. The server serializes the normalized
href from `new URL(input, event.url)`, while the client keeps the raw
string, because prerendered pages may be served from any origin. That
reasoning holds for same-origin urls, which are serialized
path-relative, but cross-origin urls are absolute on both sides, so a
raw string like `http://localhost:8080` without the trailing slash
misses the cache and the request fires a second time from the browser.

The fix normalizes `requested` to `resolved.href` in the cross-origin
case only. Normalizing in `build_selector` instead, as suggested in the
issue, would break the same-origin case, `new URL('/mock')` throws
without a base. `requested` also became a `const` derived from
`resolved` since the mutation was no longer needed.

The new test fails on main, rendering `count: 2` after the hydration
refetch overwrites the SSR data.

Not fixed here: request bodies are hashed as strings on the server but
dropped from the client hash when they are not strings, so
POST-with-body fetches still miss the cache. Can follow up separately.

Caching under the normalized href also meant a non-GET fetch spelled
without the trailing slash could no longer evict the entry, so the
second commit derives the eviction key the same way.

Also not fixed: on prerendered pages the server classifies same-origin
against `prerender.origin` while the client uses the live origin, so an
absolute url pointing at the deploy origin still misses the cache.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.
Follow-up to #16807. Instead of using a `resolveId` hook, we can use an
alias for all the generated modules — every module ID like
`<sveltekit:generated>/foo.js` corresponds to
`.svelte-kit/generated/(build|dev)/foo.js`, making things a little
easier to navigate, and reducing the cost of adding more generated
modules relative to having to faff about with plugin hooks.

The `<sveltekit:generated>` prefix is bikesheddable, but I figured it's
worth being explicit about what this is, and using characters that are
invalid in npm package names.

Creating separate directories for dev and build means we don't need to
be as careful about what goes where, and can freely use relative imports
between generated modules. It means that building while also running a
dev server won't result in clobbering.

We can easily extend this to the other virtual modules.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [ ] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <nicolas.polum@outlook.com>
Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
…ng (#16838)

#16449 made shallow `goto` run navigation hooks by copying two blocks
out of `navigate` into `update_state`: the `onNavigate` callback run
with its `afterNavigate` registration, and the completion tail (abort
check, scroll and focus reset, `fulfil`, `to.scroll`, `afterNavigate`
callbacks). #16685 then had to change both copies. They are now
`run_on_navigate_callbacks` and `finish_navigation`, called from both
places. The second commit builds `navigate`'s not-found fallback once
instead of in two branches that differ only by the message suffix.
…the file's extension (#16837)

`create_manifest_data` warns `Did you mean +${file.name}?` for any file
whose name matches either the component or the module grammar, ignoring
the extension. For `routes/a/error.ts` it suggests `+error.ts`, and
renaming to that throws `Files prefixed with + are reserved`. The two
grammars were also written out three times in the file; they're now two
module-level patterns and the typo check picks the one matching the
extension.

Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com>
…ge to the correct trailing slash (#16836)

The trailing-slash redirect for prerendered pages in
`exports/vite/preview/index.js` writes an absolute `location` from the
pathname the middleware sees, but that middleware runs inside
`scoped(base, ...)`, which has already stripped `paths.base`. With a
base path the browser lands on `/nested/` instead of `/base/nested/`.
Production (#9351) and adapter-node (#16431) send a relative location
for this reason and use 308; preview now does the same via
`relative_pathname`.

---------

Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com>
`utils/path.js` lost its only importer in #16374, `decode_params` in
#16189, `strip_virtual_prefix` in #16450.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Tee Ming <chewteeming01@gmail.com>
This PR gets rid of all the virtual modules, in favour of using real
modules in `.svelte-kit/generated`.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [ ] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Tee Ming <chewteeming01@gmail.com>
…on-existent routes (#16376)

closes #12910

When the client renders an error page for a URL that matches no route,
the root layout's server data goes missing. The universal `+layout.ts`
load receives `data: null` even though the server runs that exact load
function to render the HTML 404. Reported with `ssr = false`, but any
client-side navigation to a non-existent route hits it.

```
GET /this-route-does-not-exist/__data.json?x-sveltekit-invalidated=1

before  404 text/html          (the rendered error page)
after   200 application/json   {"type":"data","nodes":[{"type":"data","data":[{"rootlayout":1},"rootlayout"],"uses":{}}]}
```

`load_root_error_page` fetches `__data.json` when the root layout has a
server load, sending `x-sveltekit-invalidated=1` for the single root
node. The server matches no route and falls through to the `state.depth
=== 0` branch in `respond.js`, which renders the HTML error page. That
branch predates data requests, so they were never special-cased there,
and the render runs the root layout server load only to discard the
result as HTML. Client-side `load_data` then throws `HttpError(404)`,
which since #16135 is deliberately swallowed to avoid a reload loop,
leaving `server_data_node` null.

teemingc diagnosed this on the issue and named two acceptable outcomes,
"We need to be able to return layout data for an error page although a
route doesn't exist or just return the fallback error page." This PR
implements the first, server side only. The client already consumes the
response, and the fallback option would discard data the server computes
anyway while rendering the HTML 404. No client changes.

The new branch only fires for `is_data_request &&
invalidated_data_nodes?.length === 1`. The invalidation parameter marks
kit's own `load_data` fetches, so a browser navigating directly to a
`.../__data.json` URL keeps getting the HTML error page that #15884
deliberately improved (its options-2 test still passes). Length 1 is
exactly the shape `load_root_error_page` sends, so an old deployed
client requesting multi-node data for a route that no longer exists on
the new server keeps today's 404 instead of receiving a truncated nodes
array. Prerendering is excluded so a missing path still reports 404 for
dead-link detection.

The response reuses `render_data` with a synthetic root page (`layouts:
[], leaf: 0`), so load execution, serialization, streaming, redirect and
error nodes all behave as they do for matched routes. Its `route` JSDoc
is narrowed to the two fields it reads instead of casting the synthetic
object to a full `SSRRoute`. Static hosts are unaffected, there is no
server to return the data, and #16135 already keeps the fallback page
from looping there.

The new test in the basics `Errors` describe asserts both halves, JSON
with the parameter and HTML 404 without it. Fails on `version-3` without
the `respond.js` change.

Sibling PR #16380 touches the client half of this flow (reusing fresh
root layout data instead of refetching). The two compose, whichever
lands second rebases trivially.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com>
…non-ActionResult error response (#16308)

closes #15737

Submitting a `use:enhance` form that trips the CSRF origin check does
nothing visible. The 403 response is right there in the network tab:

```json
{ "message": "Cross-site POST form submissions are forbidden" }
```

but it has no `type`, so it isn't an ActionResult and every branch in
the submit handler and `applyAction` skips it. Non-JSON responses
already become `{ type: 'error' }` through the catch around
`deserialize`, so JSON that isn't an ActionResult was the one shape that
failed silently.

Error responses without a recognized `type` now throw into that same
catch and render the nearest `+error.svelte`. A body shaped like an
`App.Error` becomes `page.error` as-is, the way an `error(403, { message
})` body does. Anything else goes through `handleError`, which #16162
routed this catch through, so the hook keeps seeing these failures and
`page.error` keeps its declared shape. 2xx responses are untouched.

PatrickG suggested rendering the error page in the issue. teemingc
flagged the same gap in #10464 with a server-side shape fix in mind;
doing it on the client also covers proxy and middleware responses that
kit's server never shaped. #10855 reports the same class of unhelpful
failure for non-action endpoints; the non-2xx half of it is covered
here.

Responses that do parse as an ActionResult pass through regardless of
status, which keeps the pattern that prompted the #13197 revert (#13397)
working. The docs line that revert added says posting to a `+server.js`
endpoint results in an error; with this change that error surfaces
instead of failing silently.

The test mimics the CSRF response with an endpoint, since the real check
can't fire same-origin in Playwright. It fails on `version-3` and passes
with this change, in dev and build. The hook suffix in two of the
assertions is `handleError` running.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: Nic Polumeyv <nicolas.polum@gmail.com>
Co-authored-by: Rich Harris <rich.harris@vercel.com>
…16443)

Implements the `name` property from
#16424 (comment).

`name` is looked up from the Vite client manifest where the fonts arrays
are built, so the filter receives the exact source file name. Deriving
it from the emitted path was wrong two ways, the bundler sanitizes
characters (`inter+bold.woff2` is emitted as `inter_bold.<hash>.woff2`)
and content-identical assets are emitted once under a single name. The
union includes `name` for `font` only, kit never calls `preload` with
type `asset`.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits
- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: Rich Harris <rich.harris@vercel.com>
`read_stream` accumulates decoded text in one string, re-runs `indexOf`
over the whole buffer after every transport chunk and re-slices the
buffer for every emitted record. When one frame spans many chunks, every
prefix is rescanned and total work grows quadratically with frame size.
This parser sits behind streamed page data and remote functions (NDJSON)
and `query.live` (SSE), so the cost lands on the client for large
payloads.

With this change only newly decoded text is searched. Already searched
text accumulates in an array and is joined once per completed frame. The
last `delimiter.length - 1` characters stay in the unsearched tail so a
delimiter split across chunk boundaries still matches.

One 2 MiB frame, Node 22 x64, median of repeated runs:

| transport chunks | before | after | speedup |
| ---: | ---: | ---: | ---: |
| 2048 × 1 KiB | 1720.7 ms | 4.0 ms | 429× |
| 512 × 4 KiB | 431.0 ms | 3.2 ms | 135× |
| 128 × 16 KiB | 111.5 ms | 3.1 ms | 36× |
| 32 × 64 KiB | 31.3 ms | 3.1 ms | 10× |

Many small records, the common path, get slightly faster (2 MiB of 64
byte records in 16 KiB chunks, ~21 ms to ~15 ms) because the old code
re-sliced the buffer once per record.

Output is unchanged. The rewrite matched the previous implementation
across 4000 randomized cases covering both delimiters, delimiters split
between chunks, multibyte UTF-8 split between chunks and trailing
unterminated records. The new unit tests also pass against the previous
implementation.

`read_stream` was extracted in #15957 and last changed in #16423. No
open PR modifies `stream.js`, `ndjson.js` or `sse.js`.

---

### Before submitting the PR, please make sure you do the following

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.
…ch parameter changes (#16495)

Since #11258, `diff_search_params` compares each key's values as a set,
so navigating from `?x=a&x=a` to `?x=a` is treated as unchanged and load
functions tracking `x` don't rerun. Comparing the sorted value lists
instead catches count changes, still treats reordering as unchanged, and
is O(V log V) rather than O(V²).

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. All changesets should be `patch` until
SvelteKit 2.0 (major releases only that fix regressions)

### Edits

- [ ] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.
`core/env.js` had one generator per `<sveltekit:generated>/env/*`
module, each iterating the same variables and calling `validate()` on
the same static values, so a user's schema ran three to four times per
build (and per hot update in dev), and a validator that isn't a pure
function of its input baked different values into `config.js`,
`public/server.js` and `public/client.js`.

`create_env_modules` replaces them with a single pass over the variables
that returns every module keyed by path, so the plugin only writes
files. Dynamic variables are untouched; they were already validated once
by `set_env`.

One visible change: invalid variables that previously surfaced one
module at a time are now reported in a single error.
`client.js` walks `query_map` and `live_query_map` eight times across
`_invalidate` and `_goto`, each as a hand-written `for (const [id,
entries] of map) for (const [payload, entry] of entries)` pair, and five
of those recompute `create_remote_key(id, payload)` inline to get the
key the consumer actually wants.

This adds a `cache_entries(map)` generator yielding `[key, entry]` and
collapses each site to a single loop. No behaviour change; the walk
order and the set of resources touched are identical.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.
`handle_action_json_request` in `runtime/server/page/actions.js` was a
copy of `handle_action_request` that differed only in how each branch
was encoded, and the 405 result was written out a third time in
`handle_remote_form_post_internal`
(`runtime/server/remote-functions.js`). #16684 had to add `location` to
every copy. `handle_action_request` now runs once and
`action_result_json` encodes the result for the JSON transport;
`method_not_allowed_result` and `action_error_result` are shared with
the remote form POST handler.

The `fail()` misuse check is no longer in the shared catch, since
`fail()` is form-action only. Remote `form` handlers get a dev-time
error for a thrown or returned `fail()` in `app/server/remote/form.js`,
covering both the enhanced and no-JS transports.

`ServerActionResult` (`types/internal.d.ts`) types the pre-`handleError`
result, so we're no longer lying about the types.

---------

Co-authored-by: Rich Harris <rich.harris@vercel.com>
…6720)

closes #16696

`validate()` checks `element` before `await tick()`, but the attachment
cleanup sets `element = null` when the `<form>` unmounts. If the form is
removed while `validate()` is waiting for that tick — e.g. an `{#if}`
flips right after a fast submission — the resumed call throws:

```
TypeError: Cannot read properties of null (reading 'querySelector')
```

The fix re-checks `element` after the tick and bails out if the form is
gone, which matches what the pre-tick check already intends.

### Tests

Added a case to the `async` test app's existing `/remote/form/validate`
route: a form inside an `{#if}` block, and a button that starts
`validate()` and unmounts the form in the same handler, catching
whatever the promise rejects with. The new test fails on `version-3`
(`TypeError: Cannot read properties of null (reading 'querySelector')`)
and passes with this change.

Rebased onto `version-3` at a115a7b and re-verified locally on Node
24.18.0:

- `pnpm lint`: 0 errors (one pre-existing warning in
`src/runtime/server/page/index.js`, untouched here).
- `pnpm test:unit`: 895 passed, 11 failed. The 11 failures are in
`kit-prerendering-paths-base` and `kit-prerendering-options` and
reproduce identically on unpatched `version-3`, so they are not from
this change.
- `async` test app, `pnpm test:dev`: 193 passed, 103 skipped, 0 failed.
The new test also passes in `chromium-build` and `chromium-build-no-js`.
- `pnpm check` fails on unpatched `version-3` as well, with 24 `TS2300:
Duplicate identifier` errors from `src/types/ambient.d.ts`. This branch
changes no types, so I could not get a clean baseline for that step.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

---------

Co-authored-by: Elliott Johnson <hello@ell.iott.dev>
Co-authored-by: Rich Harris <rich.harris@vercel.com>
Four places hand-write the producer side of a stream.
`server/page/render.js` and `server/data/index.js` each construct a
`ReadableStream` whose `start` enqueues an encoded head, loops an async
iterable of chunks and closes; `form-utils.js` `LazyFile.stream()`
drives `read_range` through a `pull` adapter that re-tracks a cursor the
generator already knows; and `utils/streaming.js`
`create_async_iterator` implements `[Symbol.asyncIterator]`/`next` by
hand with two index cursors.

This replaces them with async generators and `ReadableStream.from`,
which `server/index.js` already relies on for promised `read` results.
The two response pumps share a `stream_text(head, chunks)` helper,
`LazyFile.stream()` becomes a `for await` over `read_range`, and
`iterate` becomes an `async function*` over the deferred list.

Two deliberate deltas: the response streams lose `type: 'bytes'` (added
alongside the encoding fix in #9136; `Response` only requires
`Uint8Array` chunks, which `.from` over encoded strings provides), and
an incomplete `LazyFile` now errors with an `Error` instead of a bare
string.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:
- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests
- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets
- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

---------

Co-authored-by: Rich Harris <rich.harris@vercel.com>
#16852)

`_invalidate` in `packages/kit/src/runtime/client/client.js` detects a
racing navigation by capturing `is_navigating` and bailing if it flipped
back to false. But `navigate` sets `is_navigating` only after `await
get_navigation_intent(url, false)`, which is a network round trip when
route resolution happens on the server. An `invalidate()` or
`refreshAll()` starting during that round trip sees `is_navigating ===
false`, reruns the load functions of the page being left, and applies
their result over the page the navigation just rendered.

A navigation makes an in-flight invalidation stale exactly when it
applies its result, which is also when it reassigns `current`, so
`_invalidate` now captures `current` and bails if its identity changed.

The existing test only hits the race when route resolution outlasts its
50ms `refreshAll` timer, so it passes locally and fails on loaded CI
runners. It now delays `__route.js` responses by 150ms, and fails
without the fix.

This is what turns the `test:server-side-route-resolution` legs red on
#16842.
Continuing the effort to reduce the size of `vite/index.js` so that
future Vite PRs don't cause as many merge conflicts.

This PR moves the service worker Vite plugins into their own files,
specifically, the build-only one into `vite/build` and the env var one
into the existing env var plugin file.

---------

Co-authored-by: Rich Harris <richard.a.harris@gmail.com>
I have a hunch that there are several things we can be doing to improve
the time it takes to run CI. I asked an agent to find the lowest-hanging
fruit and this is what it came up with — mostly enabling more
parallelism, though it did also remove Node 22 from the e2e test matrix,
which is possibly dangerous. Let's see how much this buys us

---------

Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <nicolas.polum@outlook.com>
…ent diagnostics (#17276)

Moves client navigation, preloading, snapshots, and form enhancement
diagnostics to the `@sveltejs/message-box` catalog. Adds client
error/warning templates with full development messages and URL-only
production output, including support for logging the relevant DOM
element alongside a warning.

Preserves the existing development guards, warning-once flags, rejection
timing, and navigation control signals. Adds browser-safe Error capture
for errors passed to handlers, plus unit and browser assertions for
production output, warning behavior, and the affected APIs.

---

<sub>Stack created with <a
href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a
href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>
Moves remote-function API misuse and shared form diagnostics to the
`@sveltejs/message-box` catalog, adding 39 diagnostic codes using the
existing server, client, and shared templates. Server-only errors keep
their full production text; client/shared errors use URL-only production
output.

Keeps validation issues, wire-error payloads, causes, live-query
cleanup, and call-site-based form warning deduplication unchanged. Adds
unit and async/basics browser coverage for these boundaries, including
production presentation and exact protocol responses. No new generator
or template contract is introduced.

---

<sub>Stack created with <a
href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a
href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>

---------

Co-authored-by: Rich Harris <rich.harris@vercel.com>
The Netlify adapter now selects its output directory using the `publish`
option, but the documentation still described reading it from
`netlify.toml`.

This PR documents the `publish` and its `build` default alongside the
other adapter options, include it in the usage example, and remove the
outdated `netlify.toml` guidance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Tee Ming <chewteeming01@gmail.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <nicolas.polum@outlook.com>
Co-authored-by: Elliott Johnson <hello+git@ell.iott.dev>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Elliott Johnson <hello@ell.iott.dev>
Co-authored-by: Conduitry <git@chor.date>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
Co-authored-by: Nic Polumeyv <162764842+Nic-Polumeyv@users.noreply.github.com>
* fix: use manual redirects for prerender fallbacks

* add a test

* fix: prevent server-side self-fetch fallbacks from following redirects
alternative to #17231 cc:
@Nic-Polumeyv

closes #17224
re-opens #17095

This PR reverts the code and test changes from #17096 

We should probably find a different fix for #17095

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [ ] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
closes #<!-- Add the related issue number here. Repeat this line for
each additional issue it closes -->

<!-- Explain the goal of the PR, why it is needed, and what has been
changed to achieve that goal -->

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [ ] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [ ] This message body should clearly illustrate what problems it
solves.
- [ ] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [ ] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [ ] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [ ] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

Co-authored-by: Tee Ming <chewteeming01@gmail.com>
The missing route-file prefix warning was still handwritten, so it had
no diagnostic code or explanation in the message catalog. Route it
through `route_file_prefix_missing` and the existing build-warning
helper.

Updates the existing test to check the diagnostic and confirm route
discovery still succeeds while ignoring unprefixed files. No new
changeset: the existing routing-diagnostics changeset covers this.
Format, lint, check, prepublish and Kit unit tests pass (1,045 passed,
110 skipped).

---------

Co-authored-by: Tee Ming <chewteeming01@gmail.com>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/kit@3.0.0-next.32

### Patch Changes

- fix: prevent non-redirect enhanced form results from navigating to
another origin
([`91aae35`](91aae35))

- fix: escape cache-control headers in prerendered HTML
([`d9d55b5`](d9d55b5))

- fix: revert route metadata caching to regenerate missing root-route
types during sync ([#17281](#17281))

- fix: print `builder.log.warn` messages to stderr, as documented
([#17253](#17253))

- fix: prevent path traversal when previewing prerendered pages and data
on Windows
([`538edbf`](538edbf))

- chore: standardize remote-function and shared form diagnostics
([#17277](#17277))

- fix: prevent server-side self-fetch fallbacks from following redirects
([`b11bb87`](b11bb87))

- chore: standardize app template diagnostics
([#17250](#17250))

- chore: standardize Vite plugin, build, prerender and adapter
diagnostics ([#17253](#17253))

- chore: standardize client navigation, preload, snapshot and
enhancement diagnostics
([#17276](#17276))

- chore: standardize configuration, environment and tsconfig diagnostics
([#17251](#17251))

- chore: standardize public API, `$app/*` and deprecated module
diagnostics ([#17265](#17265))

- chore: standardize route discovery, parameter and route export
diagnostics ([#17252](#17252))

- chore: standardize server request, hook and page diagnostics
([#17275](#17275))

- fix: report tsconfig parse errors on Windows
([#17251](#17251))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@pkg-svelte-dev

pkg-svelte-dev Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 2760a6f:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/2760a6f84ce52ee0d7ca11aa4a4342c7dd3d999e

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/17293

@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 2760a6f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
Name Type
@sveltejs/kit Major
@sveltejs/adapter-node Patch
@sveltejs/adapter-cloudflare Major
@sveltejs/adapter-vercel Patch
@sveltejs/adapter-auto Patch
@sveltejs/adapter-static Patch
@sveltejs/adapter-netlify Patch
@sveltejs/adapter-bun Patch
@sveltejs/enhanced-img Patch
@sveltejs/package Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel-security-reviewer

Copy link
Copy Markdown

Security review details

Resolve conflicts in favor of the v3 implementations, generated types, dependency versions, and platform test coverage. The deployment fixes and v2 release history are already present on version-3.
Comment thread packages/kit/src/runtime/server/sourcemaps.js Dismissed
teemingc
teemingc previously approved these changes Oct 1, 2026
Trailing-slash redirects currently return a bare final path segment. If
that segment starts with a URL scheme, browsers can interpret the
`Location` as an absolute URL and leave the original origin instead of
just adding a slash. This addresses the security review finding on
#17293.

Prefix slash-addition references with `./` in both SvelteKit's helper
and adapter-node's copy. This keeps redirects relative, preserving
stripped mount prefixes, without letting path segments become URL
schemes. Slash-removal behavior is unchanged.

Adds regression coverage for HTTP/HTTPS origins, query strings, encoded
segments, mount prefixes, dynamic routes, and prerendered paths. The new
unit regressions failed before the fix and pass afterward. Verified
formatting, lint, type checks, Kit's unit suite (1,053 passed),
adapter-node's unit suite (27 passed), and focused trailing-slash
integration tests in dev and build modes (13 passed in each).

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [ ] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

The full integration suite was not run; the unit suites, focused
dev/build integration tests, lint, and type checks passed as noted
above.

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [ ] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

The branch is in `sveltejs/kit` itself, so repository maintainers can
edit it directly.
@Rich-Harris
Rich-Harris merged commit 55ad6b0 into main Oct 1, 2026
40 of 41 checks passed
dadezzz added a commit to dadezzz/events-cash-register that referenced this pull request Oct 5, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@sveltejs/kit](https://svelte.dev) ([source](https://github.com/sveltejs/kit/tree/HEAD/packages/kit)) | [`2.70.3` → `3.0.0`](https://renovatebot.com/diffs/npm/@sveltejs%2fkit/2.70.3/3.0.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@sveltejs%2fkit/3.0.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@sveltejs%2fkit/2.70.3/3.0.0?slim=true) |

---

### Release Notes

<details>
<summary>sveltejs/kit (@&#8203;sveltejs/kit)</summary>

### [`v3.0.0`](https://github.com/sveltejs/kit/blob/HEAD/packages/kit/CHANGELOG.md#300)

[Compare Source](https://github.com/sveltejs/kit/compare/@sveltejs/kit@2.70.3...@sveltejs/kit@3.0.0)

##### Major Changes

- breaking: move remote function types to `$app/server` ([#&#8203;16740](sveltejs/kit#16740))

- breaking: remove `experimental.handleRenderingErrors` flag ([#&#8203;16265](sveltejs/kit#16265))

- breaking: make `getRequest` and `setResponse` synchronous ([#&#8203;16280](sveltejs/kit#16280))

- breaking: TypeScript 6 is now the minimum required version ([#&#8203;15930](sveltejs/kit#15930))

- breaking: refresh all load functions/queries when clicking a link to the current URL ([#&#8203;16572](sveltejs/kit#16572))

- breaking: move remote function types to `$app/server` ([#&#8203;16764](sveltejs/kit#16764))

- breaking: upgrade to `cookie` v2. Cookie names must now contain only ASCII characters ([#&#8203;13386](sveltejs/kit#13386))

- breaking: require Node 22 or newer ([#&#8203;12548](sveltejs/kit#12548))

- major: error when a client-requested single-flight mutation isn't respected by the server, allow the server to explicitly ignore refreshes ([#&#8203;16892](sveltejs/kit#16892))

- breaking: remove the `preloadStrategy` option. `modulepreload` will always be used ([#&#8203;15256](sveltejs/kit#15256))

- breaking: default the cookie `path` option to `'/'` ([#&#8203;15398](sveltejs/kit#15398))

- breaking: remove `@sveltejs/kit/node/polyfills` ([#&#8203;15430](sveltejs/kit#15430))

- breaking: add `config.kit.output.linkHeaderPreload` to preload using the `Link` header ([#&#8203;15939](sveltejs/kit#15939))

- breaking: require `@sveltejs/vite-plugin-svelte` v7 ([#&#8203;15371](sveltejs/kit#15371))

- breaking: make `page.url` immutable on a type level ([#&#8203;16256](sveltejs/kit#16256))

- breaking: remove `base`, `assets`, and `resolveRoute` from `$app/paths` ([#&#8203;15507](sveltejs/kit#15507))

- breaking: remove `createEntries` from the `Builder` object passed to adapter functions ([#&#8203;15509](sveltejs/kit#15509))

- breaking: return no content for 204 responses ([#&#8203;16200](sveltejs/kit#16200))

- breaking: rename `Pathname` type to `Path` and `Asset` to `AssetPath` ([#&#8203;16430](sveltejs/kit#16430))
  breaking: remove leading `/` from `Path` and `AssetPath`

- breaking: `handle`'s `resolve` is now typed to always return a `Promise` ([#&#8203;16352](sveltejs/kit#16352))

- breaking: remove `Server` constructor and `SSRManifest` from public types ([#&#8203;16876](sveltejs/kit#16876))

- breaking: require Svelte config options to be passed through the Vite plugin ([#&#8203;16007](sveltejs/kit#16007))

- breaking: form action responses now use the HTTP status code returned from `fail` ([#&#8203;16200](sveltejs/kit#16200))

- breaking: write tsconfig to `node_modules/$app/tsconfig` ([#&#8203;16458](sveltejs/kit#16458))

- breaking: move `defineParams` and associated types to `@sveltejs/kit/params` ([#&#8203;16716](sveltejs/kit#16716))

- breaking: remove the deprecated CSRF `checkOrigin` option in favor of `trustedOrigins` ([#&#8203;15437](sveltejs/kit#15437))

- breaking: the `delta` property now only exists for `popstate` navigation events ([#&#8203;15522](sveltejs/kit#15522))

- breaking: change `form.error` type from `any` to `App.Error | undefined` ([#&#8203;16245](sveltejs/kit#16245))

- breaking: remove deprecated `pragma` header in version polling for improved CORS support ([#&#8203;15428](sveltejs/kit#15428))

- breaking: `goto` now rejects when called with a URL that does not resolve to a route within the app, matching the existing behaviour for external URLs ([#&#8203;16164](sveltejs/kit#16164))

- breaking: run all errors through the `handleError` hook ([#&#8203;16664](sveltejs/kit#16664))

- breaking: require Svelte 5.56.4 or newer ([#&#8203;15371](sveltejs/kit#15371))

- breaking: error on `event.url`, `event.params` and `event.route` access inside queries ([#&#8203;16452](sveltejs/kit#16452))

- breaking: enhanced cross-page form actions now navigate to the action page on success and failure, matching native form behavior ([#&#8203;16684](sveltejs/kit#16684))

- breaking: delete `$service-worker` module ([#&#8203;16450](sveltejs/kit#16450))

- breaking: move `defineEnvVars` to `@sveltejs/kit/env` ([#&#8203;16375](sveltejs/kit#16375))

- breaking: nested server-only directories ([#&#8203;15685](sveltejs/kit#15685))

- feat: allow adapters to provide additional Vite plugins ([#&#8203;16206](sveltejs/kit#16206))

- breaking: replace the `$lib` alias with `#lib` and remove `files.lib` config. ([#&#8203;16360](sveltejs/kit#16360))

- breaking: remove `#lib` definition from `paths`; requires explicit module extensions as a result ([#&#8203;16736](sveltejs/kit#16736))

- chore: change `error`, `isHttpError`, `redirect`, and `isRedirect` to refer to public type instead of internal class ([#&#8203;13036](sveltejs/kit#13036))

- breaking: move hooks-related types to `@sveltejs/kit/hooks` ([#&#8203;16737](sveltejs/kit#16737))

- breaking: add 'error' result type to `preloadData` ([#&#8203;12579](sveltejs/kit#12579))

- breaking: detect new deployments on data, remote, and form action responses, tab focus, and visibility change, and default `version.pollInterval` to 1 hour ([#&#8203;16496](sveltejs/kit#16496))

- breaking: disallow cross-origin form submissions without a `Content-Type` header ([#&#8203;16347](sveltejs/kit#16347))

- breaking: Server-only directories (`/server/` in the path) are now treated as server-only everywhere inside the project (except `src/routes` and the assets directory) ([#&#8203;16360](sveltejs/kit#16360))

- breaking: `config` exported from a universal route file takes precedence over a server one ([#&#8203;16400](sveltejs/kit#16400))

- breaking: require Vite 8. Provides new functionality even for existing Vite 8 users such as faster builds with Vite hook filters and more powerful SvelteKit adapters with the Vite environment API ([#&#8203;15371](sveltejs/kit#15371))

- breaking: remove `data-sveltekit-*` option `'off'` in favour of `false` ([#&#8203;15907](sveltejs/kit#15907))

- breaking: move tracing out of the experimental namespace and remove the instrumentation flag ([#&#8203;16260](sveltejs/kit#16260))

- breaking: add `kit.paths.origin` config option, remove `kit.prerender.origin` and the `adapter-node` `ORIGIN` environment variable ([#&#8203;16161](sveltejs/kit#16161))

- breaking: move `Page`, `ReadonlyURL` and `ReadonlyURLSearchParams` from `@sveltejs/kit` to `$app/state` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: remove `$app/stores` ([#&#8203;15499](sveltejs/kit#15499))

- breaking: add `refreshAll` and deprecate `invalidateAll` ([#&#8203;16289](sveltejs/kit#16289))

- breaking: reject query parameters beginning with `x-sveltekit-` ([#&#8203;17125](sveltejs/kit#17125))

- breaking: disallow `*.remote.ts/js` files unless `experimental.remoteFunctions` is enabled ([#&#8203;16247](sveltejs/kit#16247))

- breaking: replace the `noScroll` and `keepFocus` options of `goto` with a single `reset` option, and the `data-sveltekit-noscroll` and `data-sveltekit-keepfocus` attributes with `data-sveltekit-reset` ([#&#8203;16558](sveltejs/kit#16558))

- breaking: don't abort navigation when calling `invalidate(All)` during navigation ([#&#8203;16188](sveltejs/kit#16188))

- breaking: consistent special filename patterns ([#&#8203;16382](sveltejs/kit#16382))

- breaking: allow `handleError` to influence status code ([#&#8203;16162](sveltejs/kit#16162))

- breaking: delegate CORS handling to Vite for static directory requests during development ([#&#8203;16357](sveltejs/kit#16357))

- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling stable `rolldown` 1.0.0 ([#&#8203;16134](sveltejs/kit#16134))

- breaking: only include routes with a `+page` or `+server` in `RouteId` ([#&#8203;16580](sveltejs/kit#16580))

- breaking: require Node 22.17 ([#&#8203;16597](sveltejs/kit#16597))

- breaking: deprecate `error(status, {...})` in favour of `error(status, message, {...})` ([#&#8203;16540](sveltejs/kit#16540))

- breaking: replace the `builder.generateManifest` with `builder.generateServerInstance` and `builder.manifest` ([#&#8203;16875](sveltejs/kit#16875))

- breaking: forbid external redirects by default ([#&#8203;16198](sveltejs/kit#16198))

- breaking: separate adapter Vite plugins into `pre` and `post` ([#&#8203;16711](sveltejs/kit#16711))

- breaking: remove param files in folder in favor of `params.js/ts` file ([#&#8203;16189](sveltejs/kit#16189))

- breaking: move env-related types to `@sveltejs/kit/env` ([#&#8203;16739](sveltejs/kit#16739))

- breaking: `preloadCode` now takes a route ID (e.g. `/blog/[slug]`) instead of a pathname. Route IDs are not prefixed with `paths.base` ([#&#8203;16576](sveltejs/kit#16576))

- breaking: move `BeforeNavigate`, `OnNavigate`, `AfterNavigate`, `Navigation`, `NavigationTarget`, `NavigationType`, `GotoOptions` and the `Navigation*` variant types from `@sveltejs/kit` to `$app/navigation` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: move `ActionResult` and `SubmitFunction` from `@sveltejs/kit` to `$app/forms` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: remove `handleValidationError` and pass remote function validation errors to `handleError` with `kind: 'validation'` ([#&#8203;16672](sveltejs/kit#16672))

- breaking: remove deprecated `.run()` method from live queries ([#&#8203;16573](sveltejs/kit#16573))

##### Minor Changes

- feat: allow hyphens in param and matcher names ([#&#8203;16284](sveltejs/kit#16284))

- feat: add `$app/manifest` module with `immutable`, `assets`, `prerendered`, and `routes` exports ([#&#8203;16372](sveltejs/kit#16372))

- feat: ignore files with + prefix if they contain test/spec/stories ([#&#8203;16715](sveltejs/kit#16715))

- feat: add `ErrorProps` to generated types ([#&#8203;16272](sveltejs/kit#16272))

- feat: support sourcemaps in production ([#&#8203;16412](sveltejs/kit#16412))

- feat: return the list of compressed files from `builder.compress` ([#&#8203;16566](sveltejs/kit#16566))

- feat: better response logging ([#&#8203;16744](sveltejs/kit#16744))

- feat: warn when tsconfig doesn't exclude service worker ([#&#8203;16645](sveltejs/kit#16645))

- feat: validate that all remote form fields were created with form.fields.foo.as(...) ([#&#8203;16331](sveltejs/kit#16331))

- feat: support function validators for environment variables ([#&#8203;16402](sveltejs/kit#16402))

- feat: use `type: 'module'` for service worker registrations ([#&#8203;16169](sveltejs/kit#16169))

- feat: allow adapters to receive the Svelte config as a function argument when adding Vite plugins ([#&#8203;16986](sveltejs/kit#16986))

- feat: add shallow routing to `goto` and deprecate `pushState` and `replaceState` ([#&#8203;16449](sveltejs/kit#16449))

- feat: abort `request.signal` when the response closes prematurely, via a new `response` option for `getRequest` ([#&#8203;16793](sveltejs/kit#16793))

- feat: make `$app/paths` importable in service workers ([#&#8203;16441](sveltejs/kit#16441))

- feat: pass the project-relative source `filename` to the `preload` filter for fonts ([#&#8203;16443](sveltejs/kit#16443))

- feat: preserve page state set through `goto(..., { state, persistState: true })` across reloads ([#&#8203;16449](sveltejs/kit#16449))

- feat: reinstate `$env/static/private`, `$env/dynamic/private`, `$env/static/public`, `$env/dynamic/public` and `$app/environment` as deprecated aliases for `$app/env/private` `$app/env/public` and `$app/env` ([#&#8203;16334](sveltejs/kit#16334))

- feat: add `page` and `endpoint` booleans to `$app/manifest`'s `routes`, and export a `ManifestRoute` type ([#&#8203;16594](sveltejs/kit#16594))

- feat: `$app/service-worker` module ([#&#8203;16458](sveltejs/kit#16458))

- feat: resolve paths using the Vite config `root` option instead of `process.cwd()` to better support monorepo configurations such as Vitest workspaces ([#&#8203;15469](sveltejs/kit#15469))

- feat: better error logging ([#&#8203;16374](sveltejs/kit#16374))

- feat: add `PageRouteId` and `EndpointRouteId` to `$app/types` ([#&#8203;16594](sveltejs/kit#16594))

- feat: better tsconfig validation ([#&#8203;16458](sveltejs/kit#16458))

- feat: add `dirty()` property to form fields ([#&#8203;16208](sveltejs/kit#16208))

- feat: support the `QUERY` HTTP method in `+server.js` ([#&#8203;16782](sveltejs/kit#16782))

- feat: allow adapters to override `getRequest` and `setResponse` during `vite dev` and `vite preview` ([#&#8203;16753](sveltejs/kit#16753))

- chore: deprecate `Response` helpers in favor of platform-provided alternatives ([#&#8203;15448](sveltejs/kit#15448))

- feat: add `cookies.parse` method ([#&#8203;16203](sveltejs/kit#16203))

- chore: deprecate `export const snapshot` in favour of the `snapshot` helper ([#&#8203;16687](sveltejs/kit#16687))

- feat: add `snapshot` helper to `$app/navigation` ([#&#8203;16685](sveltejs/kit#16685))

- feat: support custom values in `page.state` via `transport` hook ([#&#8203;16662](sveltejs/kit#16662))

- fix: default cookies to `secure` to `false` during development ([#&#8203;16462](sveltejs/kit#16462))

- feat: warn when naively proxying requests that result in responses with a `content-encoding` header ([#&#8203;16633](sveltejs/kit#16633))

- feat: accept the checked state as a third argument to `.as('radio', ...)` and `.as('checkbox', ...)` so that these inputs reset to it after a submission ([#&#8203;16926](sveltejs/kit#16926))

- feat: add an `applyReroute` helper for adapters that support split serverless function deployments ([#&#8203;16665](sveltejs/kit#16665))

##### Patch Changes

- fix: prevent scheme-like path segments from causing off-site trailing-slash redirects ([#&#8203;17294](sveltejs/kit#17294))

- chore: share the action error result between form actions and remote forms ([#&#8203;16835](sveltejs/kit#16835))

- fix: persist global app state across module graph reloads ([#&#8203;16663](sveltejs/kit#16663))

- fix: generate valid `Path` types for routes with optional or rest params, several params in one segment, or escape sequences ([#&#8203;16577](sveltejs/kit#16577))

- fix: coerce values typed into remote form fields, and only apply the default given to `.as()` until the field is edited ([#&#8203;16939](sveltejs/kit#16939))

- fix: blur focused SVG elements before the DOM update on navigation ([#&#8203;16983](sveltejs/kit#16983))

- fix: support bigint params in server-side route resolution ([#&#8203;17130](sveltejs/kit#17130))

- chore: build streamed responses from async generators ([#&#8203;16847](sveltejs/kit#16847))

- fix: generate types when dev server starts ([#&#8203;17034](sveltejs/kit#17034))

- fix: allow `undefined` values to be passed to form field `.as(...)` where applicable ([#&#8203;15681](sveltejs/kit#15681))

- fix: respect `paths.relative` during development for client files ([#&#8203;17053](sveltejs/kit#17053))

- fix: validate prerender concurrency ([#&#8203;17145](sveltejs/kit#17145))

- chore: deprecate `builder.rimraf` and `builder.mkdirp` in favour of `node:fs` methods ([#&#8203;16610](sveltejs/kit#16610))

- fix: manipulate stack trace for errors that happen while generating prerender inputs ([#&#8203;17113](sveltejs/kit#17113))

- fix: don't treat callable standard schemas as function param matchers ([#&#8203;16403](sveltejs/kit#16403))

- fix: prevent non-redirect enhanced form results from navigating to another origin ([#&#8203;17293](sveltejs/kit#17293))

- fix: clarify circular imports from `src/env` ([#&#8203;17014](sveltejs/kit#17014))

- fix: keep memory flat when precompressing many files ([#&#8203;16993](sveltejs/kit#16993))

- fix: render remote form actions while prerendering ([#&#8203;17139](sveltejs/kit#17139))

- fix: ignore Vitest browser loader HTML transforms ([#&#8203;17092](sveltejs/kit#17092))

- fix: prevent failed link preloads from causing unhandled promise rejections in production ([#&#8203;17181](sveltejs/kit#17181))

- fix: resolve generated rootDirs from the project root ([#&#8203;17242](sveltejs/kit#17242))

- fix: generate route resolution modules as siblings of `.html` pages ([#&#8203;16674](sveltejs/kit#16674))

- perf: parse large streamed frames in linear time ([#&#8203;16489](sveltejs/kit#16489))

- fix: keep at most one pending body read at a time when deserializing binary forms ([#&#8203;16783](sveltejs/kit#16783))

- fix: escape cache-control headers in prerendered HTML ([#&#8203;17293](sveltejs/kit#17293))

- fix: decode all numeric character references, including above `ffff`, when crawling prerendered pages ([#&#8203;16611](sveltejs/kit#16611))

- fix: enforce request body size limits when Content-Type is absent ([#&#8203;17127](sveltejs/kit#17127))

- fix: include queries refreshed from within another query in the serialized response ([#&#8203;16461](sveltejs/kit#16461))

- fix: reject malformed streamed data encoding ([#&#8203;16423](sveltejs/kit#16423))

- perf: cache the default cookie header parse and avoid allocations in `cookies.get` ([#&#8203;16341](sveltejs/kit#16341))

- fix: exclude deleted cookies from `cookies.getAll()` so it stays consistent with `cookies.get()` ([#&#8203;16297](sveltejs/kit#16297))

- fix: hide stack traces for internal errors like 404s ([#&#8203;16411](sveltejs/kit#16411))

- chore: deduplicate repeated CSP directive handling ([#&#8203;16498](sveltejs/kit#16498))

- fix: render the nearest error page when a form submission receives a non-ActionResult error response ([#&#8203;16308](sveltejs/kit#16308))

- chore: bump `mrmime` to 2.0.1 ([#&#8203;16745](sveltejs/kit#16745))

- fix: correctly implement Vite plugin hook filters ([#&#8203;16760](sveltejs/kit#16760))

- fix: ignore nested outDir files outside generated ([#&#8203;17150](sveltejs/kit#17150))

- fix: defer `query.refresh()` in server commands until after the command body completes ([#&#8203;16225](sveltejs/kit#16225))

- fix: drain unconsumed request bodies so keep-alive connections don't hang ([#&#8203;16170](sveltejs/kit#16170))

- fix: keep `history.scrollRestoration` set to `manual` when leaving the page, so a document restored from the back/forward cache does not fall back to browser scroll restoration ([#&#8203;17244](sveltejs/kit#17244))

- fix: resolve service worker and `tsconfig.json` based on Vite `root` setting ([#&#8203;16229](sveltejs/kit#16229))

- fix: rebuild the dev manifest when route files disappear during an incremental update ([#&#8203;16643](sveltejs/kit#16643))

- breaking: populate env vars before `instrumentation.server.js` is evaluated and update the adapter instrumentation API ([#&#8203;16303](sveltejs/kit#16303))

- fix: only print prerender progress newline when necessary ([#&#8203;16766](sveltejs/kit#16766))

- perf: match only unpaired surrogates when escaping HTML ([#&#8203;16407](sveltejs/kit#16407))

- fix: treat `data:` protocol URLs as external for redirect ([#&#8203;16392](sveltejs/kit#16392))

- chore: deduplicate request hashing for serialized fetch responses ([#&#8203;16499](sveltejs/kit#16499))

- fix: don't treat `Object.prototype` members as param matchers during validation ([#&#8203;16612](sveltejs/kit#16612))

- fix: generate a `never` `Path` type when there are no routes ([#&#8203;17228](sveltejs/kit#17228))

- fix: follow HTTP redirects from authentication proxies when enhancing form submissions ([#&#8203;17106](sveltejs/kit#17106))

- fix: don't report empty environment variables as missing ([#&#8203;16401](sveltejs/kit#16401))

- chore: generate the env modules in a single pass ([#&#8203;16833](sveltejs/kit#16833))

- fix: externalize `@opentelemetry/api` to prevent bundler chunk colocation between `instrumentation.server.js` and application code ([#&#8203;16302](sveltejs/kit#16302))

- fix: support form fields named after Object prototype properties ([#&#8203;17136](sveltejs/kit#17136))

- fix: exclude routes without a page or endpoint from `routes` in `$app/manifest`, and remove directories with no route files from `LayoutParams` ([#&#8203;16588](sveltejs/kit#16588))

- fix: record a history traversal before resolving its route ([#&#8203;16959](sveltejs/kit#16959))

- fix: avoid Vite dev server reload on initial page request ([#&#8203;16553](sveltejs/kit#16553))

- fix: don't set a `null` `accept-language` header on internal `fetch` sub-requests when the incoming request has none ([#&#8203;16527](sveltejs/kit#16527))

- fix: reuse SSR-cached fetch responses during hydration when a cross-origin URL is not in canonical form ([#&#8203;16339](sveltejs/kit#16339))

- fix: correctly detect prerendered paths in server `fetch` when `paths.base` is set ([#&#8203;16525](sveltejs/kit#16525))

- chore: say what a valid remote form field name looks like when rejecting one ([#&#8203;16938](sveltejs/kit#16938))

- chore: warn when remote form fields are enumerated in dev ([#&#8203;16940](sveltejs/kit#16940))

- fix: populate `$app/env/*` dynamic variables in contexts that don't run the dev server, such as `vite-node` ([#&#8203;16223](sveltejs/kit#16223))

- fix: resolve client manifest imports against the Vite root ([#&#8203;16803](sveltejs/kit#16803))

- fix: properly handle Date objects in form.fields.set ([#&#8203;16168](sveltejs/kit#16168))

- fix: return 404 for form actions and remote functions whose name is an `Object.prototype` member ([#&#8203;16072](sveltejs/kit#16072))

- fix: no longer throw "An impossible situation occurred" when a server-only module is imported by both server and client code ([#&#8203;16257](sveltejs/kit#16257))

- fix: respect Vite default log level ([#&#8203;16767](sveltejs/kit#16767))

- fix: set the focus starting point without a fragment navigation, which leaked a `hashchange` to app listeners ([#&#8203;16992](sveltejs/kit#16992))

- fix: keep a `form.for` instance registered when the derived that holds it disconnects and reconnects ([#&#8203;17230](sveltejs/kit#17230))

- fix: make cookie options optional ([#&#8203;17201](sveltejs/kit#17201))

- fix: don't duplicate remote modules in the generated manifest ([#&#8203;16532](sveltejs/kit#16532))

- fix: evict hashed fetch cache entries after mutations ([#&#8203;17146](sveltejs/kit#17146))

- chore: reuse base64 and text decoding helpers ([#&#8203;16608](sveltejs/kit#16608))

- fix: explain the removal of `$lib` and `$service-worker` when their imports fail to resolve ([#&#8203;16635](sveltejs/kit#16635))

- fix: tweak response logging for remote requests ([#&#8203;16865](sveltejs/kit#16865))

- fix: correctly massage stack traces with async frames ([#&#8203;16633](sveltejs/kit#16633))

- fix: mark `RequestEvent` properties as `readonly` ([#&#8203;16661](sveltejs/kit#16661))

- fix: render the nearest `+error.svelte` at the depth it occupies when an error is thrown during rendering ([#&#8203;16526](sveltejs/kit#16526))

- fix: support coordinate objects from image inputs in remote forms ([#&#8203;16944](sveltejs/kit#16944))

- fix: revert route metadata caching to regenerate missing root-route types during sync ([#&#8203;17281](sveltejs/kit#17281))

- chore: bump `@sveltejs/acorn-typescript` to 1.0.12 ([#&#8203;16745](sveltejs/kit#16745))

- fix: update `match` parameter type ([#&#8203;16636](sveltejs/kit#16636))

- fix: generate sourcemaps for remote modules ([#&#8203;16440](sveltejs/kit#16440))

- fix: keep hash-router links on the current document when resolving paths ([#&#8203;17107](sveltejs/kit#17107))

- fix: avoid empty getElementById() call on hash routing navigation ([#&#8203;16448](sveltejs/kit#16448))

- fix: resolve every module entry point using `kit.moduleExtensions` ([#&#8203;17043](sveltejs/kit#17043))

- fix: serve `.ico` files with `image/x-icon` Content-Type ([#&#8203;16234](sveltejs/kit#16234))

- chore: bump `magic-string` to 1.1.0 ([#&#8203;16745](sveltejs/kit#16745))

- fix: exclude inlined files from the page's `$app/manifest` immutable list ([#&#8203;16531](sveltejs/kit#16531))

- fix: discard invalidation results when a navigation completes while they load ([#&#8203;16852](sveltejs/kit#16852))

- fix: avoid client-side code being bundled by Cloudflare Wrangler ([#&#8203;16364](sveltejs/kit#16364))

- fix: wait for the redirect navigation before remote form submissions resolve ([#&#8203;16765](sveltejs/kit#16765))

- fix: record the mime types of prerendered paths in the server manifest ([#&#8203;16564](sveltejs/kit#16564))

- fix: only require the `svelte-trusted-html` trusted-types policy when client-side code is shipped, allowing builds where all pages have `csr: false` ([#&#8203;16928](sveltejs/kit#16928))

- chore: clarify which hooks run during server route resolution ([#&#8203;16397](sveltejs/kit#16397))

- fix: yield to allow prerender updates to be visible ([#&#8203;16748](sveltejs/kit#16748))

- fix: make `paths.origin` type looser ([#&#8203;16215](sveltejs/kit#16215))

- chore: bump `devalue` to 5.9.0 ([#&#8203;16745](sveltejs/kit#16745))

- feat: send periodic `keep-alive` SSE comments from `query.live` to prevent idle-timeout errors ([#&#8203;16063](sveltejs/kit#16063))

- fix: send an explicit SSE Accept header for `query.live` requests to avoid buffering by proxies ([#&#8203;17104](sveltejs/kit#17104))

- fix: don't touch the `query.live` stream controller after teardown, and make response cancellation observable via the generator's `request.signal` ([#&#8203;16790](sveltejs/kit#16790))

- fix: print `builder.log.warn` messages to stderr, as documented ([#&#8203;17253](sveltejs/kit#17253))

- fix: warn if hook files are spelled as "hook" instead of "hooks" ([#&#8203;16483](sveltejs/kit#16483))

- fix: only suggest a `+` prefix for route filenames that are valid with the file's extension ([#&#8203;16837](sveltejs/kit#16837))

- chore: only generate each route's resolution module once when prerendering ([#&#8203;16576](sveltejs/kit#16576))

- fix: don't throw from remote form `validate()` if the form unmounts while it is waiting for a tick ([#&#8203;16720](sveltejs/kit#16720))

- chore: share navigation completion between navigate and shallow routing ([#&#8203;16838](sveltejs/kit#16838))

- fix: route dev-server response logging through Vite's logger so it respects `logLevel` and `customLogger` ([#&#8203;16858](sveltejs/kit#16858))

- fix: skip clean fields when programmatically validating forms ([#&#8203;16208](sveltejs/kit#16208))

- perf: skip import graph collection outside client environments ([#&#8203;16383](sveltejs/kit#16383))

- breaking: experimental remote form `validate({ includeUntouched })` option is now `all` ([#&#8203;16208](sveltejs/kit#16208))

- fix: rerun load functions when the number of values of a tracked search parameter changes ([#&#8203;16495](sveltejs/kit#16495))

- chore: read build-time config from defines on the server instead of carrying it in `options` ([#&#8203;16873](sveltejs/kit#16873))

- fix: avoid client build warning about externalising `node:async_hooks` ([#&#8203;16244](sveltejs/kit#16244))

- chore: stop externalizing `cookie` dependency during build ([#&#8203;16936](sveltejs/kit#16936))

- fix: reinstate `$app/environment` as an alias for `$app/env`, in case dependencies import it ([#&#8203;15964](sveltejs/kit#15964))

- fix: preserve `paths.base` when `vite preview` redirects a prerendered page to the correct trailing slash ([#&#8203;16836](sveltejs/kit#16836))

- fix: error when reading non-serialized `set-cookie` headers via `getSetCookie` in `load` ([#&#8203;16614](sveltejs/kit#16614))

- fix: walk and copy directories without a stat per file ([#&#8203;16995](sveltejs/kit#16995))

- perf: avoid quadratic remote form issue merging ([#&#8203;16493](sveltejs/kit#16493))

- fix: widen remote form fields for union schemas and string enums ([#&#8203;16937](sveltejs/kit#16937))

- chore: deprecate the `alias` option ([#&#8203;16470](sveltejs/kit#16470))

- fix: don't attempt to serialize fetch responses when the request body is not a string or TypedArray ([#&#8203;16501](sveltejs/kit#16501))

- fix: respond to `HEAD` requests without a body ([#&#8203;17036](sveltejs/kit#17036))

- chore: replace deprecated Vite dev server APIs ([#&#8203;16961](sveltejs/kit#16961))

- chore: iterate the query cache maps through a single generator ([#&#8203;16846](sveltejs/kit#16846))

- fix: handle rejected streamed server data after delayed loads ([#&#8203;16268](sveltejs/kit#16268))

- fix: don't crash on interactions inside a form whose controls shadow `nodeName` ([#&#8203;16769](sveltejs/kit#16769))

- fix: don't replay a preloaded redirect when a later hop of the navigation returns to the route ([#&#8203;16955](sveltejs/kit#16955))

- fix: prevent path traversal when previewing prerendered pages and data on Windows ([#&#8203;17293](sveltejs/kit#17293))

- fix: settle a query's pending request in place when its value arrives through `set()` ([#&#8203;16958](sveltejs/kit#16958))

- fix: render pages over sibling endpoints without GET or HEAD handlers ([#&#8203;16125](sveltejs/kit#16125))

- fix: exit build workers after completing their tasks while allowing synchronous exit handlers to run ([#&#8203;17135](sveltejs/kit#17135))

- fix: prevent infinite loops when server-side queries refresh each other in a cycle during the single-flight drain ([#&#8203;16461](sveltejs/kit#16461))

- fix: populate `version` in service workers ([#&#8203;16434](sveltejs/kit#16434))

- feat: add field.touched() helper to remote form fields ([#&#8203;14692](sveltejs/kit#14692))

- fix: respect `paths.relative` for server-side route resolution imports ([#&#8203;17056](https://github.com/sveltejs/kit/pull/17056))

- fix: read the error status of `App.Error` in the `prerender` and `query.live` remote functions ([#&#8203;16529](https://github.com/sveltejs/kit/pull/16529))

- fix: resolve remote modules as external during dev prebundling so packages can re-export remote functions ([#&#8203;16426](https://github.com/sveltejs/kit/pull/16426))

- chore: standardize remote-function and shared form diagnostics ([#&#8203;17277](https://github.com/sveltejs/kit/pull/17277))

- fix: avoid `Promise.withResolvers` in client remote functions for older browser support ([#&#8203;16777](https://github.com/sveltejs/kit/pull/16777))

- fix: propagate errors from prerendered remote responses instead of re-running the function ([#&#8203;16535](https://github.com/sveltejs/kit/pull/16535))

- chore: remove unused helpers ([#&#8203;16834](https://github.com/sveltejs/kit/pull/16834))

- fix: allow reserved words (e.g. `delete`, `class`) as remote function export names ([#&#8203;16264](https://github.com/sveltejs/kit/pull/16264))

- fix: reset failed `<svelte:boundary>` on client navigation so a stale `+error.svelte` is torn down ([#&#8203;16296](https://github.com/sveltejs/kit/pull/16296))

- fix: clear `navigating` when a shallow popstate aborts an in-flight navigation ([#&#8203;17118](https://github.com/sveltejs/kit/pull/17118))

- fix: expand `[x+nn]` and `[u+nnnn]` escape sequences when resolving a route id to a pathname ([#&#8203;16570](https://github.com/sveltejs/kit/pull/16570))

- fix: respect user-set `server.cors` and `preview.cors` config instead of overriding them ([#&#8203;16924](https://github.com/sveltejs/kit/pull/16924))

- fix: respect the status returned from `handleError` on the fallback error page served to error-page sub-requests ([#&#8203;16528](https://github.com/sveltejs/kit/pull/16528))

- fix: restore scroll position after back-forward cache returns ([#&#8203;17255](https://github.com/sveltejs/kit/pull/17255))

- fix: warn if there are plugins using `transformIndexHtml` ([#&#8203;16394](https://github.com/sveltejs/kit/pull/16394))

- fix: refetch route-tracking server data when navigating away from an error page ([#&#8203;16381](https://github.com/sveltejs/kit/pull/16381))

- fix: allow routes to contain `[` and `]` via the `[x+5b]` and `[x+5d]` escapes ([#&#8203;16569](https://github.com/sveltejs/kit/pull/16569))

- chore: use `Response.json` instead of the deprecated `json` helper in runtime responses ([#&#8203;16804](https://github.com/sveltejs/kit/pull/16804))

- fix: recommend safe include and exclude patterns in tsconfig warning ([#&#8203;17102](https://github.com/sveltejs/kit/pull/17102))

- chore: remove dependency on kleur ([#&#8203;12548](sveltejs/kit#12548))

- fix: prevent server-side self-fetch fallbacks from following redirects ([#&#8203;17293](sveltejs/kit#17293))

- fix: serialize `query(...).set(...)`/`query(...).refresh()` values into the rendered HTML when called from within a query during SSR ([#&#8203;16461](sveltejs/kit#16461))

- chore: configure the server runtime in one place, deprecate `Server` in favour of the `server` object written by `builder.generateServerInstance` ([#&#8203;17000](https://github.com/sveltejs/kit/pull/17000))

- chore: derive `content-length` from fixed response bodies in `setResponse` ([#&#8203;16794](https://github.com/sveltejs/kit/pull/16794))

- fix: correctly read zero-length files at the end of a binary form payload ([#&#8203;16783](sveltejs/kit#16783))

- fix: reject fallback handlers on prerendered endpoints ([#&#8203;17140](https://github.com/sveltejs/kit/pull/17140))

- fix: don't destroy partial-line app output with the prerender progress line ([#&#8203;16750](https://github.com/sveltejs/kit/pull/16750))

- chore: remove virtual modules ([#&#8203;16813](https://github.com/sveltejs/kit/pull/16813))

- fix: surface prerender errors during development ([#&#8203;16507](https://github.com/sveltejs/kit/pull/16507))

- chore: bump `cookie` to 2.0.1 ([#&#8203;16745](sveltejs/kit#16745))

- fix: detect `$app/server` and `$app/env/private` client imports when SvelteKit is installed inside the project root ([#&#8203;16648](https://github.com/sveltejs/kit/pull/16648))

- chore: read `options` from a single module instead of passing it through the server runtime ([#&#8203;16871](https://github.com/sveltejs/kit/pull/16871))

- fix: wait for the redirect navigation before prerendered remote functions resolve ([#&#8203;16765](sveltejs/kit#16765))

- fix: sort directory entries when building the route manifest so node indices are deterministic across runtimes (e.g. Bun and Node) ([#&#8203;16074](https://github.com/sveltejs/kit/pull/16074))

- fix: skip unnecessary `version.json` checks if `updated.current` is already `true` ([#&#8203;16518](https://github.com/sveltejs/kit/pull/16518))

- fix: allow generation of $app/tsconfig without TypeScript installed ([#&#8203;16534](https://github.com/sveltejs/kit/pull/16534))

- chore: remove dependency on `set-cookie-parser` ([#&#8203;15384](https://github.com/sveltejs/kit/pull/15384))

- chore: share the nearest error page walk between client and server ([#&#8203;16774](https://github.com/sveltejs/kit/pull/16774))

- fix: fall back to the page's form actions when a sibling endpoint has no POST handler ([#&#8203;16349](https://github.com/sveltejs/kit/pull/16349))

- fix: record client output extensions in `builder.mimeTypes` ([#&#8203;16908](https://github.com/sveltejs/kit/pull/16908))

- perf: use a `Set` to check element ids when validating fragment links during prerendering ([#&#8203;16494](https://github.com/sveltejs/kit/pull/16494))

- fix: preserve shared client chunk hashes when the app version changes ([#&#8203;16324](https://github.com/sveltejs/kit/pull/16324))

- fix: include hoisted packages in Vite's `server.fs.allow` list ([#&#8203;15998](https://github.com/sveltejs/kit/pull/15998))

- chore: standardize app template diagnostics ([#&#8203;17250](https://github.com/sveltejs/kit/pull/17250))

- chore: standardize Vite plugin, build, prerender and adapter diagnostics ([#&#8203;17253](sveltejs/kit#17253))

- chore: standardize client navigation, preload, snapshot and enhancement diagnostics ([#&#8203;17276](https://github.com/sveltejs/kit/pull/17276))

- chore: standardize configuration, environment and tsconfig diagnostics ([#&#8203;17251](https://github.com/sveltejs/kit/pull/17251))

- chore: standardize public API, `$app/*` and deprecated module diagnostics ([#&#8203;17265](https://github.com/sveltejs/kit/pull/17265))

- chore: standardize route discovery, parameter and route export diagnostics ([#&#8203;17252](https://github.com/sveltejs/kit/pull/17252))

- chore: standardize server request, hook and page diagnostics ([#&#8203;17275](https://github.com/sveltejs/kit/pull/17275))

- fix: preserve metadata on streamed page responses ([#&#8203;16935](https://github.com/sveltejs/kit/pull/16935))

- fix: only include `_app/immutable` files in `$app/manifest`'s `immutable` in the service worker ([#&#8203;16531](sveltejs/kit#16531))

- chore: remove the dead `SSRState.fallback` field and name the server state fork semantics ([#&#8203;16598](https://github.com/sveltejs/kit/pull/16598))

- fix: atomically replace route metadata during sync ([#&#8203;17096](https://github.com/sveltejs/kit/pull/17096))

- fix: import resolved peer dependencies as file URLs so project-relative resolution works on Windows ([#&#8203;16618](https://github.com/sveltejs/kit/pull/16618))

- fix: preserve sourcemap source paths when adapters copy build output ([#&#8203;17082](https://github.com/sveltejs/kit/pull/17082))

- fix: log errors caught by the Vite dev server handler ([#&#8203;16550](https://github.com/sveltejs/kit/pull/16550))

- chore: bump `acorn` to 8.18.0 ([#&#8203;16745](sveltejs/kit#16745))

- fix: resolve `root` per instance of the SvelteKit Vite plugin ([#&#8203;16513](https://github.com/sveltejs/kit/pull/16513))

- fix: report tsconfig parse errors on Windows ([#&#8203;17251](https://github.com/sveltejs/kit/pull/17251))

- fix: return root layout server data for error-page data requests to non-existent routes ([#&#8203;16376](https://github.com/sveltejs/kit/pull/16376))

- fix: prevent prerender crawler from hanging on unterminated unquoted attributes ([#&#8203;17141](https://github.com/sveltejs/kit/pull/17141))

- fix: prevent `await_reactivity_loss` warning and `state_unsafe_mutation` error when the new version detector runs after an `await` ([#&#8203;16915](https://github.com/sveltejs/kit/pull/16915))

- fix: redact nested and typed underscore-prefixed remote form fields after invalid submissions ([#&#8203;17128](https://github.com/sveltejs/kit/pull/17128))

- fix: ignore path casing differences when warning about overridden Vite config on Windows ([#&#8203;16545](https://github.com/sveltejs/kit/pull/16545))

- fix: return a lightweight 404 instead of rendering the error page for subresource requests ([#&#8203;16463](https://github.com/sveltejs/kit/pull/16463))

- fix: preserve stripped path prefixes by making trailing-slash redirects relative ([#&#8203;16431](https://github.com/sveltejs/kit/pull/16431))

- fix: preserve the current URL search parameters when submitting a remote form without JavaScript ([#&#8203;16373](https://github.com/sveltejs/kit/pull/16373))

- fix: only treat files in node\_modules as remote modules when the package has a peer dependency on [@&#8203;sveltejs/kit](https://github.com/sveltejs/kit) ([#&#8203;16492](https://github.com/sveltejs/kit/pull/16492))

- fix: treeshake prerendered remote functions in the right chunks ([#&#8203;16533](https://github.com/sveltejs/kit/pull/16533))

- fix: correctly serialize Node.js buffers returned from remote functions during SSR ([#&#8203;17158](https://github.com/sveltejs/kit/pull/17158))

- fix: preserve errors with read-only stack properties ([#&#8203;17180](https://github.com/sveltejs/kit/pull/17180))

- chore: deduplicate type-stripping logic in `tweak_types` ([#&#8203;16454](https://github.com/sveltejs/kit/pull/16454))

- fix: avoid infinite loop when building with `--watch` flag ([#&#8203;16632](https://github.com/sveltejs/kit/pull/16632))

- chore: unify the `walk` and `list_files` filesystem helpers ([#&#8203;16784](https://github.com/sveltejs/kit/pull/16784))

- fix: error during development if the adapter does not support instrumentation and it exists ([#&#8203;16548](https://github.com/sveltejs/kit/pull/16548))

- fix: use mouseover+mousemove for preloading to reduce events ([#&#8203;16325](https://github.com/sveltejs/kit/pull/16325))

- fix: reject invalid binary form file metadata ([#&#8203;17149](https://github.com/sveltejs/kit/pull/17149))

- fix: error on server-only imports reachable from hooks or service worker files outside the project root ([#&#8203;16912](https://github.com/sveltejs/kit/pull/16912))

- fix: write generated tsconfig to `node_modules/$app/tsconfig.json` so that tools with simplified tsconfig resolution can find it ([#&#8203;16589](https://github.com/sveltejs/kit/pull/16589))

- chore: emit env modules to disk ([#&#8203;16807](https://github.com/sveltejs/kit/pull/16807))

- fix: more informative error message when running a command inside a query or prerender function ([#&#8203;17293](sveltejs/kit#17293))

- fix: adjust error overload for optional `App.Error` parameters ([#&#8203;16725](https://github.com/sveltejs/kit/pull/16725))

- fix: prerender and crawl pages whose `content-type` header carries a `charset` parameter ([#&#8203;16567](https://github.com/sveltejs/kit/pull/16567))

- fix: stream promised `read` results lazily instead of eagerly buffering them ([#&#8203;16622](https://github.com/sveltejs/kit/pull/16622))

- fix: copy worker files emitted by the server build to the client output directory ([#&#8203;16929](https://github.com/sveltejs/kit/pull/16929))

- chore: parse page options and remote modules with Vite's `parseSync` instead of `acorn` ([#&#8203;16947](https://github.com/sveltejs/kit/pull/16947))

- fix: correctly decode `[u+nnnn]` escape sequences above `ffff` ([#&#8203;16611](sveltejs/kit#16611))

- fix: Reject all pending query promises when a query fails before resolving with a value for the first time ([#&#8203;16890](https://github.com/sveltejs/kit/pull/16890))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzIuNSIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMi41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: Davide Zarantonello <davide@zarantonello.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.