Update dependency svelte to v5 [SECURITY] - #381
renovate[bot] wants to merge 1 commit into
Conversation
e440eb6 to
33d712d
Compare
|
No dependency changes detected. Learn more about Socket for GitHub. 👍 No dependency changes detected in pull request |
33d712d to
aa35f83
Compare
aa35f83 to
de0c040
Compare
17b5d6c to
a1ba4f1
Compare
a1ba4f1 to
9bb7c98
Compare
9bb7c98 to
49a51d2
Compare
7e3f2c2 to
2db0263
Compare
950f211 to
1e15d83
Compare
dacf32a to
04a37fb
Compare
44f828c to
2072ab7
Compare
WalkthroughSvelte devDependency updated from version 3.55.0 to 4.0.0 in packages/ui/package.json. This major version bump transitions the build environment to Svelte 4.x, affecting compatibility with the framework's latest generation. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes 🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches
🧪 Generate unit tests (beta)
📝 Coding Plan
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
14f1ab3 to
474f631
Compare
a29720e to
f8f1890
Compare
f8f1890 to
b978ef4
Compare
b714572 to
5b2e412
Compare
60a869f to
7c3c38a
Compare
a44b0ce to
bdb1807
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
⛔ Files ignored due to path filters (1)
yarn.lockis excluded by!**/yarn.lock,!**/*.lock
📒 Files selected for processing (1)
packages/ui/package.json(1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: build (solidity, default)
- GitHub Check: semgrep-cloud-platform/scan
| "rollup-plugin-svelte": "^7.2.3", | ||
| "rollup-plugin-terser": "^7.0.2", | ||
| "svelte": "^3.55.0", | ||
| "svelte": "^4.0.0", |
There was a problem hiding this comment.
🧩 Analysis chain
✓ Approve the security fix, but verify build compatibility.
The version bump addresses CVE-2024-45047, a critical XSS vulnerability in Svelte's SSR that affects attribute escaping in <noscript> tags. The ^4.0.0 constraint ensures v4.2.19+ (which includes the fix) will be installed.
However, this is a major version change. Verify that:
- The build completes without errors.
- All tests pass with Svelte v4.
- The compatibility of related dependencies (rollup-plugin-svelte v7.2.3, svelte-check v3.8.6, svelte-preprocess v5.1.4) is confirmed.
🏁 Script executed:
#!/bin/bash
# Description: Verify build and test compatibility with Svelte v4.
set -e
cd packages/ui
# Check if rollup-plugin-svelte v7.2.3 is compatible with Svelte v4
echo "Checking package.json for compatible versions..."
grep -E '"(svelte|rollup-plugin-svelte|svelte-check|svelte-preprocess)"' package.json
# Try to resolve and validate dependencies (without installing)
npm list svelte rollup-plugin-svelte svelte-check svelte-preprocess 2>&1 | head -20 || echo "npm list may fail if not installed; this is expected"
# Check for known breaking changes or migration notes
echo ""
echo "Checking Svelte v4 migration documentation..."
# Look for any v4-specific documentation or migration guides in the repo
fd -e md -e txt --type f | xargs grep -l "svelte.*v4\|svelte.*4\.0\|migration" 2>/dev/null | head -5 || echo "No migration docs found"Length of output: 292
🌐 Web query:
rollup-plugin-svelte v7.2.3 Svelte v4 compatibility
💡 Result:
Yes — rollup-plugin-svelte v7.2.3 is compatible with Svelte 4. The Svelte v4 migration docs require rollup-plugin-svelte >= 7.1.5 for Rollup users, and v7.2.3 is a current 7.x release. [1][2]
Sources:
[1] rollup-plugin-svelte on npm (v7.2.3).
[2] Svelte v4 migration guide — "If you are using Rollup, upgrade to rollup-plugin-svelte 7.1.5 or higher."
🌐 Web query:
svelte-check v3.8.6 Svelte v4 support
💡 Result:
Yes — svelte-check 3.8.6 lists Svelte v4 in its peerDependencies and its 3.8.6 release notes show Svelte v4/5-related fixes, so v3.8.6 supports Svelte 4. [1][2]
Sources:
- package-lock entry showing peerDependencies include ^4.0.0. [1]
- svelte-check 3.8.6 release notes. [2]
🌐 Web query:
Svelte v4 breaking changes migration guide
💡 Result:
Here are the essential steps and breaking changes to handle when migrating to Svelte v4 — run the automatic migrator first, then address the manual items below.
Quick steps
- Run the migrator: npx svelte-migrate@latest svelte-4. [1]
- Upgrade toolchain: Node >= 16, TypeScript >= 5, Vite/SvelteKit/rollup/webpack plugin versions listed in the guide. [1]
- Update eslint to eslint-plugin-svelte (eslint-plugin-svelte3 is deprecated). [1]
Top breaking changes to check and fix
- Compiler output is ESM-only (CJS output and svelte/register removed). If you need CJS, convert ESM to CJS in a post-build step. [1]
- Stricter TypeScript typings: createEventDispatcher, Action generic types, and onMount return types now enforce correctness — update types accordingly. [1]
- Transitions are local by default and default slot bindings behavior changed — review components that relied on the old globals. [1]
- Custom elements and svelte component instance accessors changed (SvelteComponentTyped deprecated; custom-elements docs). [1]
- Browser/build config: bundlers must use the "browser" condition (misconfigured bundlers can cause lifecycle hooks like onMount not to run). Update rollup/webpack/Vite config as documented. [1]
- Store API changes: StartStopNotifier must now provide an update function; derived() throws on falsy values instead of treating them as stores. [1]
- Runtime changes affecting very old browsers: classList.toggle(name, boolean), CustomEvent constructor usage, and the inert attribute applied to outroing elements — polyfills may be necessary. [1]
- DOM removals are batched (order of removal/events may differ; MutationObserver users should verify). [1]
- Global JSX/typing namespace changes: migrate from svelte.JSX to svelteHTML / svelte/elements where applicable. [1]
If you want, I can:
- run the migrator commands you should execute,
- produce a checklist tailored to your repo (package.json, bundler, and TypeScript files) — share your repo or package.json.
🏁 Script executed:
#!/bin/bash
# Description: Examine rollup config and check for Svelte v4 breaking change patterns
echo "=== Checking rollup configuration ==="
fd -e "rollup.config" -o -e "rollup.js" | head -5
echo ""
echo "=== Checking for store API usage patterns ==="
fd -e svelte -e ts -e js | xargs grep -l "StartStopNotifier\|writable\|derived" 2>/dev/null | head -10
echo ""
echo "=== Checking for TypeScript issues (Action, createEventDispatcher) ==="
fd -e svelte -e ts | xargs grep -l "Action\|createEventDispatcher" 2>/dev/null | head -10
echo ""
echo "=== Checking for SvelteComponentTyped usage ==="
fd -e svelte -e ts -e js | xargs grep -l "SvelteComponentTyped" 2>/dev/null | head -5
echo ""
echo "=== Checking for ESM/CJS output config ==="
fd -e "package.json" --type f | xargs grep -l "exports\|module\|main" 2>/dev/null | head -10Length of output: 730
🌐 Web query:
svelte-preprocess v5.1.4 Svelte v4 support
💡 Result:
Yes — svelte-preprocess v5.1.4 is compatible with Svelte v4. The package README documents using svelte-preprocess for Svelte (and notes Svelte 4 users still need a preprocessor for TypeScript and common CSS preprocessors), and the v5.1.4 npm release is available. [1][2]
Sources:
- svelte-preprocess v5.1.4 on npm. [1]
- svelte-preprocess README / usage (compatibility notes). [2]
🏁 Script executed:
#!/bin/bash
# Description: Verify SvelteComponentTyped usage and check rollup config
echo "=== SvelteComponentTyped usage in Wiz.svelte ==="
grep -n "SvelteComponentTyped" packages/ui/src/common/Wiz.svelte -B2 -A2
echo ""
echo "=== Checking for rollup.config file ==="
find packages/ui -name "rollup.config.*" -o -name "rollup.js" | head -5
echo ""
echo "=== Checking package.json exports field ==="
cat packages/ui/package.json | grep -A5 '"exports"' || echo "No exports field found"Length of output: 500
🏁 Script executed:
#!/bin/bash
# Description: Check rollup config for Svelte v4 setup and look for alternative SvelteComponentTyped patterns
echo "=== rollup.config.mjs content (first 50 lines) ==="
head -50 packages/ui/rollup.config.mjs
echo ""
echo "=== Checking if there are other deprecated patterns in Wiz.svelte ==="
cat packages/ui/src/common/Wiz.svelte | head -50Length of output: 3433
Critical issue: SvelteComponentTyped is deprecated in Svelte v4—migration incomplete.
The version upgrade is valid and addresses CVE-2024-45047 (XSS in SSR). All dependencies (rollup-plugin-svelte v7.2.3, svelte-check v3.8.6, svelte-preprocess v5.1.4) are compatible with Svelte v4, and the rollup configuration is properly set up.
However, packages/ui/src/common/Wiz.svelte (lines 2, 25–26) uses SvelteComponentTyped, which is deprecated and removed in Svelte v4. This must be updated to the new component typing pattern before the upgrade can proceed. Run the migration tool—npx svelte-migrate@latest svelte-4—to help identify and fix all breaking changes, particularly in this file and any TypeScript type usage (createEventDispatcher, Action generics).
🤖 Prompt for AI Agents
packages/ui/src/common/Wiz.svelte (referenced lines 2, 25-26): Svelte v4 removed
SvelteComponentTyped so update the component typings and related TypeScript
usages: run the migration tool npx svelte-migrate@latest svelte-4 to auto-fix
common breaking changes, then edit Wiz.svelte to replace SvelteComponentTyped
usages with the new Svelte v4 typing patterns (use the new
Component/props/events/slots generics or export component types per the
migration output), update createEventDispatcher and Action generics to their v4
signatures, fix any resulting type errors, and re-run the typechecker/build
until type errors are resolved.
This PR contains the following updates:
^3.55.0→^5.0.0Svelte has a potential mXSS vulnerability due to improper HTML escaping
CVE-2024-45047 / GHSA-8266-84wp-wv5c
More information
Details
Summary
A potential XSS vulnerability exists in Svelte for versions prior to 4.2.19.
Details
Svelte improperly escapes HTML on server-side rendering. It converts strings according to the following rules:
"->"&->&<-><&->&The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leveraged to perform XSS attacks. More specifically, this can occur when injecting malicious content into an attribute within a
<noscript>tag.PoC
A vulnerable page (
+page.svelte):If a user accesses the following URL,
then,
alert(123)will be executed.Impact
XSS, when using an attribute within a noscript tag
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte affected by cross-site scripting via spread attributes in Svelte SSR
CVE-2026-27121 / GHSA-f7gr-6p89-r883
More information
Details
Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering. When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR does not validate dynamic element tag names in
<svelte:element>CVE-2026-27122 / GHSA-m56q-vw4c-c2cp
More information
Details
When using
<svelte:element this={tag}>in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR attribute spreading includes inherited properties from prototype chain
CVE-2026-27125 / GHSA-crpf-4hrx-3jrp
More information
Details
In server-side rendering, attribute spreading on elements (e.g.
<div {...attrs}>) enumerates inherited properties from the object's prototype chain rather than only own properties. In environments whereObject.prototypehas already been polluted — a precondition outside of Svelte's control — this can cause unexpected attributes to appear in SSR output or cause SSR to throw errors. Client-side rendering is not affected.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte vulnerable to XSS during SSR with contenteditable
bind:innerTextandbind:textContentCVE-2026-27901 / GHSA-phwv-c562-gvmh
More information
Details
The contents of
bind:innerTextandbind:textContentoncontenteditableelements were not properly escaped. This could enable HTML injection and Cross-site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR vulnerable to cross-site scripting via spread attributes
CVE-2026-42599 / GHSA-pr6f-5x2q-rwfp
More information
Details
When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires.
This is similar to but different from CVE-2026-27121.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
CVE-2026-42573 / GHSA-rcqx-6q8c-2c42
More information
Details
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.
You are vulnerable if all of the following is true:
nameattribute on an input or button element within that formSeverity
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
sveltejs/svelte (svelte)
v5.55.7Compare Source
Patch Changes
fix: prevent XSS on
hydratablefrom user contents (a16ebc67bbcf8f708360195687e1b2719463e1a4)chore: bump devalue (#18219)
fix: disallow empty attribute names during SSR (
547853e2406a2147ad7fb5ffeba95b01bd9642da)fix: harden regex (
d2375e2ebcab5c88feb5652f1a9d621b8f06b259)fix: move Svelte runtime properties to symbols (
e1cbbd96441e82c9eb8a23a2903c0d06d3cda991)v5.55.6Compare Source
Patch Changes
fix: leave stale promises to wait for a later resolution, instead of rejecting (#18180)
fix: keep dependencies of
$state.eager/pending(#18218)fix: reapply context after transforming error during SSR (#18099)
fix: don't rebase just-created batches (#18117)
chore: allow
nullforpendingin typings (#18201)fix: flush eager effects in production (#18107)
fix: rethrow error of failed iterable after calling
return()(#18169)fix: account for proxified instance when updating
bind:this(#18147)fix: ensure scheduled batch is flushed if not obsolete (#18131)
fix: resolve stale deriveds with latest value (#18167)
chore: remove unnecessary
increment_pendingcalls (#18183)fix: correctly compile component member expressions for SSR (#18192)
fix: reset
source.updatedstack traces afterflush(#18196)fix: replacing async 'blocking' strategy with 'merging' (#18205)
fix: allow
@debugtags to reference awaited variables (#18138)fix: re-run fallback props if dependencies update (#18146)
fix: abort running obsolete async branches (#18118)
fix: ignore comments when reading CSS values (#18153)
fix: wrap
Promise.allinsaveduring SSR (#18178)fix: ignore false-positive errors of
$inspectdependencies (#18106)v5.55.5Compare Source
Patch Changes
fix: don't mark deriveds while an effect is updating (#18124)
fix: do not dispatch introstart event with animation of animate directive (#18122)
v5.55.4Compare Source
Patch Changes
fix: never mark a child effect root as inert (#18111)
fix: reset context after waiting on blockers of
@constexpressions (#18100)fix: keep flushing new eager effects (#18102)
v5.55.3Compare Source
Patch Changes
fix: ensure proper HMR updates for dynamic components (#18079)
fix: correctly calculate
@constblockers (#18039)fix: freeze deriveds once their containing effects are destroyed (#17921)
fix: defer error boundary rendering in forks (#18076)
fix: avoid false positives for reactivity loss warning (#18088)
v5.55.2Compare Source
Patch Changes
fix: invalidate
@consttags based on visible references in legacy mode (#18041)fix: handle parens in template expressions more robustly (#18075)
fix: disallow
--inidPrefix(#18038)fix: correct types for
ontoggleon<details>elements (#18063)fix: don't override
$destroy/set/oninstance methods in dev mode (#18034)fix: unskip branches of earlier batches after commit (#18048)
fix: never set derived.v inside fork (#18037)
fix: skip rebase logic in non-async mode (#18040)
fix: don't reset status of uninitialized deriveds (#18054)
v5.55.1Compare Source
Patch Changes
fix: correctly handle bindings on the server (#18009)
fix: prevent hydration error on async
{@html ...}(#17999)fix: cleanup
superTypeParametersinClassDeclarations/ClassExpression(#18015)fix: improve duplicate module import error message (#18016)
fix: reschedule new effects in prior batches (#18021)
v5.55.0Compare Source
Minor Changes
Patch Changes
v5.54.1Compare Source
Patch Changes
fix: hydration comments during hmr (#17975)
fix: null out
effect.bindestroy_effect(#17980)fix: group sync statements (#17977)
fix: defer batch resolution until earlier intersecting batches have committed (#17162)
fix: properly invoke
iterator.return()during reactivity loss check (#17966)fix: remove trailing semicolon from {@const} tag printer (#17962)
v5.54.0Compare Source
Minor Changes
css,runes,customElementcompiler options to be functions (#17951)Patch Changes
v5.53.13Compare Source
Patch Changes
fix: ensure
$inspectafter top level await doesn't break builds (#17943)fix: resume inert effects when they come from offscreen (#17942)
fix: don't eagerly access not-yet-initialized functions in template (#17938)
fix: discard batches made obsolete by commit (#17934)
fix: ensure "is standalone child" is correctly reset (#17944)
fix: remove nodes in boundary when work is pending and HMR is active (#17932)
v5.53.12Compare Source
Patch Changes
fix: update
select.__valueonchange(#17745)chore: add
invarianthelper for debugging (#17929)fix: ensure deriveds values are correct across batches (#17917)
fix: handle async RHS in
assignment_value_stale(#17925)fix: avoid traversing clean roots (#17928)
v5.53.11Compare Source
Patch Changes
fix: remove
untrackcircular dependency (#17910)fix: recover from errors that leave a corrupted effect tree (#17888)
fix: properly lazily evaluate RHS when checking for
assignment_value_stale(#17906)fix: resolve boundary in correct batch when hydrating (#17914)
chore: rebase batches after process, not during (#17900)
v5.53.10Compare Source
Patch Changes
v5.53.9Compare Source
Patch Changes
bind:thiscleanup timing (#17885)v5.53.8Compare Source
Patch Changes
fix:
{@html}no longer duplicates content insidecontenteditableelements (#17853)fix: don't access inert block effects (#17882)
fix: handle asnyc updates within pending boundary (#17873)
perf: avoid re-traversing the effect tree after
$:assignments (#17848)chore: simplify scheduling logic (#17805)
v5.53.7Compare Source
Patch Changes
fix: correctly add __svelte_meta after else-if chains (#17830)
perf: cache element interactivity and source line splitting in compiler (#17839)
chore: avoid rescheduling effects during branch commit (#17837)
perf: optimize CSS selector pruning (#17846)
fix: preserve original boundary errors when keyed each rows are removed during async updates (#17843)
perf: avoid O(n²) name scanning in scope
generateandunique(#17844)fix: preserve each items that are needed by pending batches (#17819)
v5.53.6Compare Source
Patch Changes
perf: optimize parser hot paths for faster compilation (#17811)
fix:
SvelteMapincorrectly handles keys withundefinedvalues (#17826)fix: SvelteURL
searchsetter now returns the normalized value, matching native URL behavior (#17828)fix: visit synthetic value node during ssr (#17824)
fix: always case insensitive event handlers during ssr (#17822)
chore: more efficient effect scheduling (#17808)
perf: optimize compiler analysis phase (#17823)
fix: skip redundant batch.apply (#17816)
chore: null out current_batch before committing branches (#17809)
v5.53.5Compare Source
Patch Changes
fix: escape
innerTextandtextContentbindings ofcontenteditable(0df5abcae223058ceb95491470372065fb87951d)fix: sanitize
transformErrorvalues prior to embedding in HTML comments (0298e979371bb583855c9810db79a70a551d22b9)v5.53.4Compare Source
Patch Changes
fix: set server context after async transformError (#17799)
fix: hydrate if blocks correctly (#17784)
fix: handle default parameters scope leaks (#17788)
fix: prevent flushed effects from running again (#17787)
v5.53.3Compare Source
Patch Changes
fix: render
:catchof#awaitblock with correct key (#17769)chore: pin aria-query@5.3.1 (#17772)
fix: make string coercion consistent to
toString(#17774)v5.53.2Compare Source
Patch Changes
fix: update expressions on server deriveds (#17767)
fix: further obfuscate
node:cryptoimport from overzealous static analysis (#17763)v5.53.1Compare Source
Patch Changes
v5.53.0Compare Source
Minor Changes
feat: allow comments in tags (#17671)
feat: allow error boundaries to work on the server (#17672)
Patch Changes
fix: use TrustedHTML to test for customizable
<select>support, where necessary (#17743)fix: ensure head effects are kept in the effect tree (#17746)
chore: deactivate current_batch by default in unset_context (#17738)
v5.52.0Compare Source
Minor Changes
{@html}expressions (#17701)Patch Changes
fix: repair dynamic component truthy/falsy hydration mismatches (#17737)
fix: re-run non-render-bound deriveds on the server (#17674)
v5.51.5Compare Source
Patch Changes
fix: check to make sure
svelte:elementtags are valid during SSR (73098bb26c6f06e7fd1b0746d817d2c5ee90755f)fix: misc option escaping and backwards compatibility (#17741)
fix: strip event handlers during SSR (
a0c7f289156e9fafaeaf5ca14af6c06fe9b9eae5)fix: replace usage of
for inwithfor of Object.keys(f89c7ddd7eebaa1ef3cc540400bec2c9140b330c)fix: always escape option body in SSR (
f7c80da18c215e3727c2a611b0b8744cc6e504c5)chore: upgrade
devalue(#17739)v5.51.4Compare Source
Patch Changes
chore: proactively defer effects in pending boundary (#17734)
fix: detect and error on non-idempotent each block keys in dev mode (#17732)
v5.51.3Compare Source
Patch Changes
fix: prevent event delegation logic conflicting between svelte instances (#17728)
fix: treat CSS attribute selectors as case-insensitive for HTML enumerated attributes (#17712)
fix: locate Rollup annontaion friendly to JS downgraders (#17724)
fix: run effects in pending snippets (#17719)
v5.51.2Compare Source
Patch Changes
fix: take async into consideration for dev delegated handlers (#17710)
fix: emit state_referenced_locally warning for non-destructured props (#17708)
v5.51.1Compare Source
Patch Changes
fix: don't crash on undefined
document.contentType(#17707)fix: use symbols for encapsulated event delegation (#17703)
v5.51.0Compare Source
Minor Changes
TrustedTypesfor HTML handling where supported (#16271)Patch Changes
fix: sanitize template-literal-special-characters in SSR attribute values (#17692)
fix: follow-up formatting in
print()— flush block-level elements into separate sequences (#17699)fix: preserve delegated event handlers as long as one or more root components are using them (#17695)
v5.50.3Compare Source
Patch Changes
fix: take into account
nodeNamecase sensitivity on XHTML pages (#17689)fix: render
multipleandselectedattributes as empty strings for XHTML compliance (#17689)fix: always lowercase HTML elements, for XHTML compliance (#17664)
fix: freeze effects-inside-deriveds when disconnecting, unfreeze on reconnect (#17682)
fix: propagate
$effecterrors to<svelte:boundary>(#17684)v5.50.2Compare Source
Patch Changes
fix: resolve
effect_update_depth_exceededwhen usingbind:valueon<select>with derived state in legacy mode (#17645)fix: don't swallow
DOMExceptionwhenmedia.play()fails inbind:paused(#17656)chore: provide proper public type for
parseCssresult (#17654)fix: robustify blocker calculation (#17676)
fix: reduce if block nesting (#17662)
v5.50.1Compare Source
Patch Changes
fix: render boolean attribute values as empty strings for XHTML compliance (#17648)
fix: prevent async render tag hydration mismatches (#17652)
v5.50.0Compare Source
Minor Changes
Patch Changes
fix: ensure infinite effect loops are cleared after flushing (#17601)
fix: allow
{#key NaN}(#17642)fix: detect store in each block expression regardless of AST shape (#17636)
fix: treat
<menu>like<ul>/<ol>for a11y role checks (#17638)fix: add vite-ignore comment inside dynamic crypto import (#17623)
chore: wrap JSDoc URLs in
@seeand@linktags (#17617)fix: properly hydrate already-resolved async blocks (#17641)
fix: emit
each_key_duplicateerror in production (#16724)fix: exit resolved async blocks on correct node when hydrating (#17640)
v5.49.2Compare Source
Patch Changes
chore: remove SvelteKit data attributes from elements.d.ts (#17613)
fix: avoid erroneous async derived expressions for blocks (#17604)
fix: avoid Cloudflare warnings about not having the "node:crypto" module (#17612)
fix: reschedule effects inside unskipped branches (#17604)
v5.49.1Compare Source
Patch Changes
fix: merge consecutive large text nodes (#17587)
fix: only create async functions in SSR output when necessary (#17593)
fix: properly separate multiline html blocks from each other in
print()(#17319)fix: prevent unhandled exceptions arising from dangling promises in <script> (#17591)
v5.49.0Compare Source
Minor Changes
ShadowRootInitobject to custom elementshadowoption (#17088)Patch Changes
fix: throw for unset
createContextget on the server (#17580)fix: reset effects inside skipped branches (#17581)
fix: preserve old dependencies when updating reaction inside fork (#17579)
fix: more conservative assignment_value_stale warnings (#17574)
fix: disregard
popoverelements when determining whether an element has content (#17367)fix: fire introstart/outrostart events after delay, if specified (#17567)
fix: increment signal versions when discarding forks (#17577)
v5.48.5Compare Source
Patch Changes
fix: run boundary
onerrorcallbacks in a microtask, in case they result in the boundary's destruction (#17561)fix: prevent unintended exports from namespaces (#17562)
fix: each block breaking with effects interspersed among items (#17550)
v5.48.4Compare Source
Patch Changes
v5.48.3Compare Source
Patch Changes
fix: hydration failing with settled async blocks (#17539)
fix: add pointer and touch events to a11y_no_static_element_interactions warning (#17551)
fix: handle false dynamic components in SSR (#17542)
fix: avoid unnecessary block effect re-runs after async work completes (#17535)
fix: avoid using dev-mode array.includes wrapper on internal array checks (#17536)
v5.48.2Compare Source
Patch Changes
waitfunction from internal client index (#17530)v5.48.1Compare Source
Patch Changes
fix: hoist snippets above const in same block (#17516)
fix: properly hydrate await in
{@html}(#17528)fix: batch resolution of async work (#17511)
fix: account for empty statements when visiting in transform async (#17524)
fix: avoid async overhead for already settled promises (#17461)
fix: better code generation for const tags with async dependencies (#17518)
v5.48.0Compare Source
Minor Changes
parseCssfromsvelte/compiler(#17496)Patch Changes
fix: handle non-string values in
svelte:elementthisattribute (#17499)fix: faster deduplication of dependencies (#17503)
v5.47.1Compare Source
Patch Changes
selectedcontentreactivity (#17486)v5.47.0Compare Source
Minor Changes
<select>elements (#17429)Patch Changes
fix: mark subtree of svelte boundary as dynamic (#17468)
fix: don't reset static elements with debug/snippets (#17477)
v5.46.4Compare Source
Patch Changes
devalue.unevalto serializehydratablekeys (ef81048e238844b729942441541d6dcfe6c8ccca)v5.46.3Compare Source
Patch Changes
fix: reconnect clean deriveds when they are read in a reactive context (#17362)
fix: don't transform references of function declarations in legacy mode (#17431)
fix: notify deriveds of changes to sources inside forks (#17437)
fix: always reconnect deriveds in get, when appropriate (#17451)
fix: prevent derives without dependencies from ever re-running (
286b40c4526ce9970cb81ddd5e65b93b722fe468)fix: correctly update writable deriveds inside forks (#17437)
fix: remove
$inspectcalls after await expressions when compiling for production server code (#17407)fix: clear batch between runs (#17424)
fix: adjust
locproperty ofProgramnodes created from<script>elements (#17428)fix: don't revert source to UNINITIALIZED state when time travelling (#17409)
v5.46.1Compare Source
Patch Changes
fix: type
currentTargetinonfunction (#17370)fix: skip static optimisation for stateless deriveds after
await(#17389)fix: prevent infinite loop when HMRing a component with an
await(#17380)v5.46.0Compare Source
Minor Changes
cspoption torender(...), and emit hashes when usinghydratable(#17338)v5.45.10Compare Source
Patch Changes
AsyncLocalStorage(#17350)v5.45.9Compare Source
Patch Changes
fix: correctly reschedule deferred effects when reviving a batch after async work (#17332)
fix: correctly print
!doctypeduringprint(#17341)v5.45.8Compare Source
Patch Changes
fix: set AST
root.startto0androot.endtotemplate.length(#17125)fix: prevent erroneous
state_referenced_locallywarnings on prop fallbacks (#17329)v5.45.7Compare Source
Patch Changes
fix: Add
<textarea wrap="off">as a valid attribute value (#17326)fix: add more css selectors to
print()(#17330)fix: don't crash on
hydratableserialization failure (#17315)v5.45.6Compare Source
Patch Changes
fix: don't issue a11y warning for
<video>without captions if it has nosrc(#17311)fix: add
srcObjectto permitted<audio>/<video>attributes (#17310)v5.45.5Compare Source
Patch Changes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.