sveltejs/kit
63.8
Adequate · 1 October 2026
38.1k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is the SvelteKit framework, a full-stack web application toolkit that manages routing, server-side rendering, and client-side navigation. It provides utilities for data loading, form actions, and state management, alongside deployment adapters and build engine logic. The codebase also includes a comprehensive test suite that validates these core capabilities, including static prerendering, error handling, and development server behaviors.
How it got here
2020–2022 — SvelteKit 3.0.0 release and testing
169 changes.
This period focused on the development and release of SvelteKit 3.0.0, which introduced breaking changes including migration to Vite 8, adoption of Svelte 5 Runes, and replacement of legacy stores. The work involved rewriting core adapters to support the new build system and runtime requirements while simultaneously expanding the test suite to cover new features and edge cases.
2023–2025 — async runtime and remote functions
123 changes.
This period focused on introducing a full-async runtime, featuring a new $app/state module for reactive navigation data and a remote functions API for server-side code execution from the browser. The work also included a rewritten enhanced-img plugin for Vite 5, improved postbuild crawling infrastructure, and extensive test coverage for these new features and adapter integrations.
2026 — remote functions and adapter expansion
58 changes.
This period focused on introducing experimental remote functions with client-side caching and live updates, alongside the release of new adapters for Bun and Cloudflare. Significant work also went into standardizing error messaging with documentation links and expanding test coverage for environment variable security, form enhancements, and various adapter integrations.
Features
Add TypeScript definitions for enhanced-img
This change introduces TypeScript declaration files for the enhanced-img package, providing type safety for users. It defines the \Picture\ type from \vite-imagetools\ and exports \EnhancedImgAttributes\, ensuring that the \src\ prop for dynamic image imports uses the correct object type rather than a string. It also augments Svelte's DOM types to recognize the \enhanced:img\ custom element, allowing it to accept both string paths and \Picture\ objects for its \src\ attribute. Additionally, internal types for Svelte AST nodes are exposed for use within the package's implementation.
packages/enhanced-img/types · high confidence
Add basic SvelteKit playground template
Introduces a new minimal SvelteKit application structure in the \playgrounds/basic\ directory, providing a starting point for development. This includes the core application shell (\app.html\ with viewport meta tags), type definitions (\app.d.ts\), a root layout component, a default home page displaying 'hello!', and configuration for the service worker.
playgrounds/basic · high confidence
Add virtual Cloudflare Workers module for development environment
The adapter now includes a new virtual module (\virtual-cloudflare-workers.js\) that provides a development-time implementation of the Cloudflare Workers API. This module exposes proxies for environment variables (\env\), tracing (\tracing\), and cache (\cache\), allowing applications to access Cloudflare-specific bindings and features during local Vite dev or preview sessions without requiring a full Workers runtime.
packages/adapter-cloudflare/src · high confidence
Added funding manifest URL
A new .well-known/funding-manifest-urls file has been added to the repository, pointing to https://svelte.dev/funding.json. This allows tools and users to discover the project's funding information via the standard well-known URI path.
.well-known · high confidence
Added test utility for parsing environment variables
A new \test-utils/index.js\ module has been introduced, providing a \number\_from\_env\ helper function. This utility reads a specified environment variable, converts its value to a number, and throws an error if the value cannot be parsed, ensuring robust handling of numeric configuration in tests.
test-utils · high confidence
Automated generation of localized message modules and JSON manifest
A new script in the Kit package now processes Markdown message definitions from the \messages\ directory, using \@sveltejs/message-box\ to parse and render them into generated JavaScript modules in \src/messages\ and a consolidated \messages.json\ file in the documentation assets. This change introduces a build-time step that transforms human-readable message files into structured, type-safe exports and a machine-readable manifest, ensuring duplicate message codes are detected and output is consistently formatted.
packages/kit/scripts/process-messages · high confidence
Default error page now supports dark mode
The default error page template (src/error.html) has been updated to include dark mode styles. When the user's system prefers a dark color scheme, the error page will automatically switch to a dark background and light text, improving readability and consistency with the user's OS preferences.
packages/kit/src/core/config · high confidence
Initial Cloudflare Workers adapter implementation
This change introduces the core files for the new Cloudflare Workers adapter, including the TypeScript configuration, internal type definitions, and the main worker entry point. The worker initializes the SvelteKit server with access to Cloudflare environment bindings and an ASSETS\_BINDING for fetching static files. It handles request routing by distinguishing between static assets, prerendered pages, and dynamic endpoints, ensuring proper caching headers for static content and providing the client's IP address via the \cf-connecting-ip\ header for dynamic requests.
packages/adapter-cloudflare/files · high confidence
Initial release of SvelteKit v3.0.0
This change introduces the initial codebase for SvelteKit version 3.0.0, establishing the core CLI entry point (\cli.js\) which currently supports the \sync\ command for generating type definitions and environment variables. It defines essential runtime constants for HTTP methods (including support for the QUERY method), path suffixes for data and route resolution, and telemetry stubs, while exporting the \VERSION\ constant to identify the release.
packages/kit/src · high confidence
Internal runtime modules for environment validation and error handling
SvelteKit introduces new internal modules in \packages/kit/src/exports/internal\ to support runtime environment variable validation and standardized error handling. The \env.js\ module implements validation logic using the Standard Schema specification, allowing developers to define validators for environment variables and reporting issues like missing values or invalid configurations. The \shared.js\ module provides core error classes including \HttpError\, \HandledHttpError\, \SvelteKitError\, \ActionFailure\, and \ValidationError\, which are used throughout the runtime for consistent error handling. The \client.js\ module exports client-specific utilities like \get\_origin()\. These internal modules form the foundation for the explicit environment variables feature and improved error handling capabilities.
packages/kit/src/exports/internal · high confidence
Introduce $app/state module for reactive page and navigation data
SvelteKit now exposes a new \$app/state\ module that provides read-only, reactive objects for \page\, \navigating\, and \updated\. The \page\ object allows components to access current route data, URL, params, and form state using Svelte runes, while \navigating\ tracks in-progress navigation details. The \updated\ object helps detect new deployments by polling for version changes. This module is split into client and server implementations, with the server side restricting access to the render phase to ensure data consistency.
packages/kit/src/runtime/app/state · high confidence
Introduce @sveltejs/adapter-bun for Bun runtime deployment
Adds a new official adapter for deploying SvelteKit applications on the Bun runtime. The adapter builds the server using Vite (instead of a separate Bun build pass) and supports generating single-file executables via \buildOptions.compile\. It includes native static file serving with precompression (brotli/gzip), configurable environment variable prefixes, and graceful shutdown handling. The package requires Bun 1.4 or newer.
packages/adapter-bun · high confidence
Introduce \`svelte-kit sync\` command for generated file management
SvelteKit now includes a dedicated \svelte-kit sync\ command to generate and maintain project-specific files, including the client and server manifests, TypeScript type definitions, and explicit environment variable modules. This new \packages/kit/src/core/sync\ module centralizes the logic for writing these artifacts, allowing the CLI to trigger generation on demand rather than only during builds, and supports incremental updates when route files change.
packages/kit/src/core/sync · high confidence
Introduce client-side runtime for remote functions
This change adds the client-side implementation for the new remote functions feature, introducing a caching system that manages the lifecycle of query and live-query resources using FinalizationRegistry for automatic eviction. It provides the client-side counterparts for server-side primitives, including \command\ for mutations, \form\ for enhanced form handling with preflight validation and state management, \query\ and \query\_live\ for data fetching, and \prerender\ for caching prerendered data in the browser's Cache API. The implementation also includes a \query\_batch\ mechanism to deduplicate and batch concurrent query requests, ensuring efficient network usage and consistent state across the application.
packages/kit/src/runtime/client/remote-functions · high confidence
Introduce server-side remote functions (command, form, query, prerender)
SvelteKit now supports server-side remote functions, allowing you to define functions in \.remote.ts\ files that can be called from the browser via fetch. This location provides the server-side runtime implementations for four function types: \command\ for mutations, \form\ for validated form submissions, \query\ for data fetching with caching, and \prerender\ for static site generation. The implementation includes a shared validation layer using Standard Schema, request context isolation to prevent access to restricted properties like \event.url\ in queries, and specific handling for client-requested refreshes via the \requested\ helper.
packages/kit/src/runtime/app/server/remote · high confidence
Isomorphic caching for client-side remote queries
Client-side remote queries now use an isomorphic caching system that deduplicates requests sharing the same ID and arguments, automatically evicts cache entries when proxies are garbage collected, and supports manual overrides via \withOverride\ to keep cache entries alive during reactive updates.
packages/kit/src/runtime/client/remote-functions/query · high confidence
New $app/forms module for client-side form enhancement
SvelteKit introduces a dedicated \$app/forms\ module that exports \enhance\, \applyAction\, and \deserialize\ to manage form submissions on the client. The \enhance\ action intercepts form submissions to provide JavaScript-enhanced behavior—such as resetting forms, refreshing data, navigating to the result location, and following redirects—while preserving native form functionality when JavaScript is unavailable. This module also provides type definitions for \ActionResult\ and \SubmitFunction\ to support typed form handling in TypeScript projects.
packages/kit/src/runtime/app/forms · high confidence
New $app/manifest module re-exports generated app manifest
A new \packages/kit/src/runtime/app/manifest/index.js\ file has been added, which re-exports all bindings from the generated \\<sveltekit:generated\>/app-manifest.js\ module. This provides a standardized runtime entry point for accessing the application's manifest data.
packages/kit/src/runtime/app/manifest · high confidence
New $app/paths runtime API for assets, routing, and path matching
SvelteKit now exposes a unified \$app/paths\ module (importable in both client and server contexts) that provides \asset()\, \resolve()\, and \match()\ functions. The \asset()\ function resolves static files by prefixing them with the configured assets path or base path, while \resolve()\ constructs URLs for route IDs or pathnames, correctly handling base paths and hash routing modes. The new \match()\ function allows developers to reverse-resolve a URL to its corresponding route ID and parameters, enabling dynamic routing logic on both client and server sides.
packages/kit/src/runtime/app/paths · high confidence
New $app/server exports for reading assets and accessing request context
The \packages/kit/src/runtime/app/server\ module now exposes a \read\ function that allows server-side code to read the contents of imported assets (including handling data URIs and base64 decoding) and a \getRequestEvent\ function to access the current request context. Additionally, remote form utilities (\query\, \prerender\, \command\, \form\, \requested\) are re-exported from this location, providing a centralized entry point for server-side form handling and remote function interactions.
packages/kit/src/runtime/app/server · high confidence
New TypeScript declaration files for internal modules and app types
The Kit package now ships with new \.d.ts\ files in \packages/kit/src/types\ that provide TypeScript definitions for internal generated modules (such as \\<sveltekit:generated\>/server.js\ and \\<sveltekit:generated\>/app-manifest.js\) and the public \$app/manifest\ and \$app/types\ modules. These files define the shapes of environment variable handling, route manifests, and route ID types, ensuring that TypeScript users receive accurate type checking and autocompletion for these internal and manifest-related APIs.
packages/kit/src/types · high confidence
New \`defineParams\` API for standardized route parameter matching
The \@sveltejs/kit/params\ export now provides a \defineParams\ function that allows you to define route parameter matchers using either traditional functions or Standard Schema V1 compliant validators (such as ArkType or Valibot). This change normalizes these definitions into a unified matcher interface, enabling type-safe parameter validation and transformation directly within your app's routing configuration.
packages/kit/src/exports/params · high confidence
New enhanced-img plugin with Vite 5 and Vite-Imagetools integration
The \enhanced-img\ package has been rewritten to support Vite 5 and integrates with \vite-imagetools\ to automatically optimize images. The new implementation uses a Vite plugin to transform \\<enhanced:img\>\ tags into responsive \\<picture\>\ elements, applying default directives for formats (avif, webp, and a fallback like jpg or png) and generating multiple width variants based on viewport sizes. It also includes logic to handle dynamic image sources, resolve asset paths, and provide better error handling for missing images.
packages/enhanced-img/src · high confidence
New internal scripts for dependency checking, test reporting, and app synchronization
Added three new scripts to the \scripts\ directory to support development and CI workflows. \check-dependencies.js\ analyzes the monorepo to identify duplicate dependency versions across packages. \print-flaky-test-report.js\ handles the output of flaky tests by reading from a temporary file, ensuring proper formatting on Windows. \sync-all.js\ iterates through test application directories (apps, build-errors, prerendering) to synchronize SvelteKit manifest data, helping to eliminate warnings in CI.
scripts · high confidence
New internal server modules for request context, remote functions, and telemetry
This change introduces new internal server modules in \packages/kit/src/exports/internal/server\ that provide core runtime capabilities. The \event.js\ module implements \getRequestEvent\ and \get\_request\_store\ to access the current request context using Node's \AsyncLocalStorage\ (with a synchronous fallback for environments like WebContainers), ensuring the event is only accessible synchronously. The \remote-functions.js\ module adds validation for remote function modules, rejecting default exports and non-remote exports while assigning unique IDs. The \telemetry.js\ module integrates OpenTelemetry tracing, initializing the tracer and providing a \record\_span\ function that automatically captures attributes and error details for HTTP errors, redirects, and generic errors, with proper handling for when tracing is disabled or the API is missing. Tests cover these new behaviors, including AsyncLocalStorage availability, remote function validation, and telemetry attribute recording.
packages/kit/src/exports/internal/server · high confidence
New postbuild analysis and crawling infrastructure
The postbuild phase now uses a dedicated \analyse.js\ module to validate server exports, resolve route entries, and check feature compatibility before prerendering. A new \crawl.js\ module provides a lightweight, dependency-free HTML crawler that extracts IDs, hrefs, and meta tags, supported by a bundled \entities.js\ decoder for correct character handling. These components are backed by new test suites (\crawl.spec.js\, \entities.spec.js\, \queue.spec.js\) and a concurrency \queue.js\ utility to manage prerender tasks.
packages/kit/src/core/postbuild · high confidence
New server-side form action handling and data serialization infrastructure
This change introduces the core server-side logic for handling form actions, including the \actions.js\ module which manages action request routing, validation, and JSON response formatting. It also adds \data\_serializer.js\ to handle the serialization of server load data (including promises) into script payloads, and \respond\_with\_error.js\ to manage error page rendering and fatal error responses. These components are supported by new test suites in \actions.spec.js\, \csp.spec.js\, \data\_serializer.spec.js\, and \load\_data.spec.js\ that verify action location handling, CSP nonce generation, serialization errors, and fetch behavior.
packages/kit/src/runtime/server/page · high confidence
New static analysis module for SvelteKit page options
A new static analysis module has been added to the Vite plugin to parse and validate page options (such as \ssr\, \prerender\, \csr\, \trailingSlash\, and \config\) from \+page.js\ and \+layout.js\ files. This module uses Vite's \parseSync\ to safely extract literal values while ignoring dynamic expressions, reassignments, and exports that cannot be statically resolved. It also includes utilities to detect child content rendering in Svelte files and to correctly ignore page option declarations that appear within comments or strings, preventing false warnings for users who comment out or string-escape these options.
_packages/kit/src/exports/vite/static\analysis · high confidence
New utility functions for array, CSS, and filesystem operations
Added several new utility modules to the kit package: \array.js\ provides a \compact\ function to filter nullish values; \css.js\ introduces \fix\_css\_urls\ to correct asset paths in CSS before inlining and \tippex\_comments\_and\_strings\ to safely parse CSS values; \filesystem.js\ adds \copy\ for recursive directory copying with sourcemap rebasing and string replacement, \walk\ for directory traversal, and \resolve\_entry\ for finding entry files; \escape.js\ exports \escape\_html\ for HTML attribute and text escaping with surrogate handling, and \escape\_for\_interpolation\ for template literal safety; \exports.js\ defines validators for route file exports; \format.js\ adds \join\_or\ and \bullet\_list\ for diagnostic formatting; \functions.js\ includes \once\ for single-execution wrapping and \disallow\_on\_server\ for runtime checks; \hash.js\ provides \hash\ and \hash\_request\ for content hashing; \http.js\ adds \negotiate\ for Accept header parsing, \matches\_content\_type\ for content-type checking, and \is\_form\_content\_type\ for CSRF protection; \import.js\ and \imports.js\ handle peer dependency resolution and package.json imports field parsing; \mime.js\ extends mrmime with \.ico\ support; and \os.js\ provides a \posixify\ path normalizer. Comprehensive test suites were added for these utilities.
packages/kit/src/utils · high confidence
Repository initialization with development tooling and configuration
The repository is initialized with essential configuration files to standardize development workflows. An \.editorconfig\ enforces LF line endings, UTF-8 charset, and tab indentation. A \.gitattributes\ file ensures consistent line endings and excludes test fixtures from language detection. A \.gitignore\ file filters out build artifacts, environment variables, and platform-specific directories. Code formatting is configured via \.oxfmtrc.json\ (replacing Prettier) with specific rules for Svelte and package READMEs. AI coding assistance is supported through \AGENTS.md\ and \CLAUDE.md\. Developer guidance is provided in \CONTRING.md\, while \eslint.config.js\ sets up linting rules, including custom checks to prevent runtime code from importing build-pipeline modules. Dependency management is handled by \pnpm-workspace.yaml\ (defining packages, catalogs, and overrides) and \renovate.json\ (automating updates). Finally, \tsconfig.json\ and \vitest.config.js\ configure TypeScript type checking and the Vitest test runner for the monorepo.
(repo-wide) · high confidence
Support for function-based validators in environment variable definitions
The \defineEnvVars\ utility in \@sveltejs/kit/env\ now accepts plain functions as the \schema\ property for environment variables, in addition to Standard Schema objects. This allows developers to define custom validation and transformation logic using simple functions that return a value or throw an error, which are automatically normalized to the Standard Schema format at runtime. This change simplifies the configuration of environment variables by removing the requirement to import a specific schema library for basic validation needs.
packages/kit/src/exports/env · high confidence
Security
Block cross-site form POSTs by default
The server runtime now includes built-in CSRF protection that blocks cross-site form submissions (POST, PUT, PATCH, DELETE) when the request origin does not match the app's self-origin. The self-origin is derived from the configured \paths.origin\ if set, otherwise from the request URL. Requests can be allowed by listing their origin in the \csrf\_trusted\_origins\ configuration. Remote function requests are also blocked if they are non-GET and cross-origin, with no trusted origins bypass.
packages/kit/src/runtime/server · high confidence
API
New centralized type definitions in packages/kit/types
The \packages/kit/types\ directory now contains a single, comprehensive \index.d.ts\ file that consolidates the framework's public type definitions. This change introduces the \Adapter\ and \AdapterViteConfig\ interfaces, allowing adapters to configure Vite plugins and override request/response handling functions. It also defines the \Builder\ interface used during the build process, exposing methods like \generateFallback\ and \generateEnvModule\, alongside core types such as \ActionFailure\ and \ValidationError\ for form handling.
packages/kit/types · high confidence
Architecture
Refactored core build logic into dedicated modules
The core build logic in \packages/kit/src/core\ has been reorganized into specific modules: \env.js\ now handles explicit environment variable loading and module generation, \params.js\ manages route parameter matcher validation, \features.js\ checks adapter support for specific capabilities, and \utils.js\ provides shared utilities like the runtime directory path and logging. This change improves code maintainability and separation of concerns within the Kit core.
packages/kit/src/core · high confidence
SvelteKit Vite plugin restructured into modular exports
The SvelteKit Vite plugin has been reorganized from a single monolithic file into a modular structure under \packages/kit/src/exports/vite\. The main entry point (\index.js\) now acts as a coordinator, importing dedicated plugins for environment variables, service workers, remote functions, and compilation from separate files. This change introduces new utility modules for handling configuration aliases, normalizing module IDs, and detecting server-only or remote modules, alongside updated TypeScript definitions (\public.d.ts\) that reflect the current configuration interface. This restructuring improves maintainability and allows for more granular control over the Vite plugin lifecycle.
packages/kit/src/exports/vite · high confidence
Behavioural changes
Centralized transport serialization logic in runtime
The runtime now centralizes transport-related serialization logic by introducing a new \transport.js\ module. This module provides \init\_transport\ to configure custom encoders and decoders, replacing the previous behavior where serialization functions like \stringify\, \parse\, and \uneval\ were likely handled differently or scattered. Users relying on custom transport mechanisms will now have their custom encode/decode functions registered through this centralized initialization, ensuring consistent data handling across the application.
packages/kit/src/runtime/app/internal · high confidence
Client-side live query implementation with SSE and caching
The \query.live\ remote function now uses Server-Sent Events (SSE) for real-time updates on the client, replacing previous streaming mechanisms. This change introduces a client-side caching layer (\CacheController\) that deduplicates live queries by key and manages their lifecycle, ensuring that multiple consumers of the same query share a single connection. The implementation includes a \LiveQueryProxy\ that supports async iteration and promise-like semantics, along with automatic reconnection logic and error handling for network interruptions.
packages/kit/src/runtime/client/remote-functions/query-live · high confidence
Customize changelog generation to reduce noise and automate GitHub releases
The project now uses a custom changelog generator that simplifies dependency updates by listing only package names and versions, avoiding redundant links to internal changesets. GitHub release notes are automatically generated using the standard template, and the configuration ensures that only packages within the @sveltejs scope are tracked for changelog entries.
.changeset · high confidence
Deprecated $env/\* modules in favor of $app/env/\*
The \$env/dynamic/private\, \$env/dynamic/public\, \$env/static/private\, and \$env/static/public\ modules are now deprecated. In development mode, importing these modules triggers a warning directing users to use the new \$app/env/private\ and \$app/env/public\ equivalents instead. The old modules remain functional for backward compatibility but serve only as re-exports of the new internal paths.
packages/kit/src/runtime/env · high confidence
Deprecation warning for $app/environment module
The $app/environment module now emits a deprecation warning when used in development mode, signaling that it is being phased out in favor of $app/env. This change supports the transition to a standardized public API while maintaining backwards compatibility for existing dependencies that may still import the older path.
packages/kit/src/runtime/app/environment · high confidence
Explicit environment variable exports in $app/env
The $app/env module now explicitly exports environment-related constants (browser, dev, building, version) and provides separate entry points for public and private environment variables. This change clarifies which variables are available on the client versus the server, and introduces a mechanism to close a potential security loophole where private server-side environment variables could be inadvertently exposed to the client.
packages/kit/src/runtime/app/env · high confidence
Implement Vite preview server with prerendered page handling and custom server support
The \vite/preview\ module now provides the complete logic for the SvelteKit preview server, including initializing the server runtime via the adapter's \configure\ hook, serving static client assets, and handling prerendered pages with correct trailing slash redirects and ETag caching. It also supports custom server entry points, HTTP/2, instrumentation hooks, and properly handles Chrome DevTools workspace requests and URI decoding for prerendered assets.
packages/kit/src/exports/vite/preview · high confidence
Improved request body handling and connection stability in Node adapter
The Node adapter now enforces body size limits more strictly by rejecting requests that exceed the configured limit with a 413 status, even when the Content-Type header is absent. It also fixes a connection hang issue on keep-alive sockets by automatically draining unconsumed request bodies after the response is sent, ensuring that pipelined requests are not lost. Additionally, the adapter now aborts the request signal if the response closes prematurely, improving resource cleanup.
packages/kit/src/exports/node · high confidence
Internal path resolution logic moved to dedicated client/server modules
The internal implementation for resolving application paths has been split into separate \client.js\ and \server.js\ files within the \internal\ directory. This change isolates the runtime logic, allowing the client-side module to support service worker contexts (while explicitly blocking the \match\ function there) and providing server-side specific exports like \relative\ and a \set\_assets\ setter. This structural shift prepares the codebase for the new universal \\#app/paths\ subpath import mechanism.
packages/kit/src/runtime/app/paths/internal · high confidence
Navigation module reorganization and server-side safety
The navigation exports in \packages/kit/src/runtime/app/navigation\ have been restructured: \client.js\ now re-exports client-side functions (like \goto\, \invalidate\, \beforeNavigate\) from the core client module, while \server.js\ provides safe no-op or disallowing stubs for these same functions to prevent runtime errors during server-side rendering. Additionally, \public.d.ts\ introduces comprehensive TypeScript definitions for navigation types (e.g., \NavigationTarget\, \GotoOptions\, \NavigationType\) and deprecates older options like \replaceState\ and \invalidateAll\ in favor of \replace\ and \refreshAll\.
packages/kit/src/runtime/app/navigation · high confidence
New @sveltejs/kit/hooks entry point with sequence helper and deprecated defineEnvVars
The hooks module is now exported from a dedicated \@sveltejs/kit/hooks\ entry point, providing the \sequence\ helper for chaining multiple \handle\ hooks in a middleware-like manner. The \sequence\ function merges \transformPageChunk\ options in reverse order, while \preload\ and \filterSerializedResponseHeaders\ options use a first-defined-wins strategy. A deprecated \defineEnvVars\ function remains in this entry point but now throws an error directing users to the new \@sveltejs/kit/env\ module. The public type definitions for hooks (Handle, HandleServerError, HandleClientError, etc.) are also included in this new entry point.
packages/kit/src/exports/hooks · high confidence
New ESLint rules enforce import boundaries and Windows path safety
Three new ESLint rules have been added to the project's linting configuration to improve code quality and cross-platform compatibility. The \no-exports-to-runtime-imports\ rule prevents importing from \src/exports\ into \src/runtime\, while \no-runtime-to-exports-imports\ blocks relative imports from \src/runtime\ to \src/exports\ to avoid Vite resolution conflicts. Additionally, the \require-path-to-file-url\ rule mandates that dynamic imports of computed file paths use \pathToFileURL\ (or \new URL\ with a base) to prevent failures on Windows where absolute paths are incorrectly parsed as URLs.
.eslint · high confidence
New build scripts for type bundling and version generation
The \packages/kit/scripts\ directory now includes three new utility scripts: \generate-dts.js\ bundles TypeScript declarations from various source modules (including \$app/\\ and \@sveltejs/kit/\\ subpaths) into a single \types/index.d.ts\ file while stripping internal types and guarding against broken imports; \generate-version.js\ reads the package version and writes it to \src/version.js\ for export; and \cp.js\ provides a simple file copy utility. These changes support the new type declaration bundling strategy and version management for the Kit package.
packages/kit/scripts · high confidence
New builder API for adapters with explicit environment configuration
The adapter build process now uses a new \create\_builder\ function that accepts an \explicit\_env\_config\ parameter, allowing adapters to receive validated environment variable configurations directly. This change introduces a stable \RouteDefinition\ facade for route filtering and grouping, replaces the deprecated \builder.createEntries\ with \builder.routes\, and adds a \builder.generateFallback\ method for generating fallback pages. The builder also includes improved compression handling with memory-efficient parallel processing and Windows-compatible path posixification for instrumentation files.
packages/kit/src/core/adapt · high confidence
New dev-mode manifest generation and server runtime entry point
The dev server now uses a dedicated \generate\_manifest\ module to construct the SSR manifest, introducing lazy loading for components and server modules, inlining CSS styles to prevent FOUC, and supporting remote chunks. The main dev entry point (\index.js\) initializes the Vite SSR runner, enforces that \global.fetch\ is not called with relative URLs during development, and routes response logging through Vite's logger.
packages/kit/src/exports/vite/dev · high confidence
New modular tsconfig generation and validation logic
The SvelteKit kit package now uses a dedicated \write\_tsconfig\ module to generate and validate the \tsconfig.json\ files it manages. This change introduces a new generated base config at \node\_modules/$app/tsconfig.json\ (and a separate one for service workers) that user configs must extend. The system now validates that essential compiler options (like \verbatimModuleSyntax\ and \isolatedModules\) are not overwritten, that path aliases and type definitions are preserved, and that the service worker file is correctly excluded. It also provides clearer warnings if the user's config fails to extend the generated base or if TypeScript parse errors occur, and it gracefully handles environments where TypeScript is not installed by skipping validation in those cases.
_packages/kit/src/core/sync/write\tsconfig · high confidence
New runtime error handling and form utilities
The runtime now includes dedicated modules for error chain resolution and form data processing. The new error-chain.js module ensures that +error.svelte components are rendered at the correct depth in the component tree, fixing issues where error pages were not displayed at the right nesting level. The new form-utils.js module introduces a binary form serialization format (application/x-sveltekit-formdata) for more efficient file uploads and data transfer, along with improved handling of nested object fields, type coercion for numbers and booleans, and protection against prototype pollution attacks in form field names.
packages/kit/src/runtime · high confidence
New server data rendering entry point with streaming support
The server runtime now uses a dedicated \render\_data\ function in \packages/kit/src/runtime/server/data/index.js\ to handle data requests. This implementation consolidates the logic for loading server data nodes, handling errors, and managing redirects. It supports both standard JSON responses (for non-streamed data) and streaming responses using a proprietary \text/sveltekit-data\ content type when chunks are present, ensuring proper cache control and version headers are applied to all data responses.
packages/kit/src/runtime/server/data · high confidence
New service worker runtime entry point with strict context validation
A new runtime entry point at \packages/kit/src/runtime/app/service-worker/index.js\ has been added to standardize the service worker execution context. This module exports a typed \self\ object to ensure correct TypeScript types for service workers, provided the consuming module uses the appropriate \$app/tsconfig/service-worker\ configuration. In development mode, it includes a runtime check that throws an error if the module is executed outside of a valid \ServiceWorkerGlobalScope\, preventing misuse of the service worker API in non-worker contexts.
packages/kit/src/runtime/app/service-worker · high confidence
New type generation entry point and test suite for route types
The \packages/kit/src/core/sync/write\_types\ directory now contains the primary entry point (\index.js\) for generating TypeScript definitions for SvelteKit routes, along with a comprehensive test suite (\index.spec.js\). The new \index.js\ module introduces \write\_all\_types\ and \write\_types\ functions that manage the lifecycle of generated \$types.d.ts\ files, including detecting stale types, cleaning up obsolete files, and tracking metadata to ensure types stay in sync with route source files. The accompanying tests verify that the internal \tweak\_types\ helper correctly rewrites TypeScript and JavaScript load functions to inject proper type annotations, ensuring that generated types are valid and usable by the TypeScript compiler.
_packages/kit/src/core/sync/write\types · high confidence
Node adapter rewritten with new environment variable handling and static asset serving
The adapter-node source has been completely rewritten to introduce a new, strict environment variable configuration system. A new \env.js\ module validates that environment variables (such as \HOST\, \PORT\, \BODY\_SIZE\_LIMIT\, and new timeout settings like \KEEP\_ALIVE\_TIMEOUT\ and \HEADERS\_TIMEOUT\) match expected names and formats, throwing errors for invalid values. The static asset serving logic in \static.js\ has been replaced with a new file-map-based middleware that handles content negotiation (gzip/brotli), immutable caching for specific asset paths, and trailing-slash redirects for prerendered pages. The main server entry point (\index.js\) now supports systemd socket activation and implements graceful shutdown with configurable timeouts, while the request handler (\handler.js\) uses the new synchronous \getRequest\ and \setResponse\ APIs from SvelteKit.
packages/adapter-node/src · high confidence
Pre-push hook enforces lockfile integrity and runs linting
A new pre-push hook has been added to the repository that automatically runs before code is pushed. It executes \pnpm install --frozen-lockfile\ to ensure dependencies match the lockfile exactly, followed by \pnpm lint\ and \pnpm check\ to verify code quality and type safety. This ensures that only code passing these checks and using the exact specified dependencies is pushed.
.githooks · high confidence
Refactored Vite plugin architecture and fixed server-only import guard for external entrypoints
The Vite plugin logic in this package has been reorganized into dedicated modules (env-vars, guard, remote) to improve maintainability and align with updated Vite APIs. A critical fix ensures the server-only import guard correctly detects violations when entrypoints (such as hooks) are located outside the project root, preventing accidental client-side imports of server code in those scenarios. Additionally, environment variable modules are now generated in a single pass and written to disk, and the remote functions plugin has been updated to use aliases instead of a resolveId hook for better resolution handling.
packages/kit/src/exports/vite/plugins · high confidence
Refactored client runtime entry points and added scroll/focus management modules
The client runtime has been restructured to support new bundling strategies and improved navigation state handling. A new \bundle.js\ entry point was added to handle 'single' and 'inline' bundle strategies, while \entry.js\ manages the 'split' strategy by lazily importing the client. New dedicated modules for \scroll.js\ and \focus.js\ now handle scroll restoration and focus reset logic, including support for disabling scroll handling via \disable\_scroll\_handling()\. Snapshot management was also moved to a new \snapshots.js\ module, and streaming utilities (\stream.js\, \ndjson.js\, \sse.js\) were added to support parsing streamed data and Server-Sent Events.
packages/kit/src/runtime/client · high confidence
Refactored route manifest generation with conflict detection and deterministic sorting
The \create\_manifest\_data\ module has been restructured to improve the reliability and correctness of route discovery. A new \conflict.js\ module now detects and prevents routing conflicts, specifically handling permutations caused by optional parameters to ensure unique route IDs. Route sorting logic has been extracted into \sort.js\ to provide deterministic ordering of routes regardless of filesystem entry order, which is critical for consistent client-side and server-side manifest generation. The main \index.js\ entry point now orchestrates these components, and \types.d.ts\ has been updated to reflect the internal data structures used during manifest creation.
_packages/kit/src/core/sync/create\_manifest\data · high confidence
Refactored server build pipeline to use a new \`build\_server\_nodes\` module
The server-side build logic has been reorganized into a dedicated \build\_server\_nodes\ module, which is now responsible for generating the server node entry points and handling CSS inlining. This change introduces a new \plugin\_compile\ Vite plugin to orchestrate the build process and a \treeshake\_prerendered\_remotes\ utility to optimize remote function chunks. Additionally, the service worker build is now handled by a separate \plugin\_service\_worker\_build\ module, and the build utilities have been updated to support the new Rolldown-based build API.
packages/kit/src/exports/vite/build · high confidence
Refactored server manifest generation to improve asset tracking and routing accuracy
The manifest generation logic in \packages/kit/src/core/generate\_manifest\ has been restructured to ensure more accurate server-side asset discovery and routing data. A new \find\_server\_assets.js\ module now explicitly collects assets imported by server files, hooks, and universal nodes, ensuring these are correctly recorded in the manifest's \server\_assets\ map with their file sizes and MIME types. The main \index.js\ generator now filters out unused nodes (excluding prerendered routes) while guaranteeing that root layout and error nodes are always included, and it properly resolves symlinks for endpoint chunks. This results in a smaller, more precise manifest that correctly serves static assets with their recorded Content-Types and prevents unnecessary data requests during client-side navigation.
_packages/kit/src/core/generate\manifest · high confidence
Removal of legacy $app stores in favor of $app/state
The legacy \$app/stores\ module has been removed; importing \getStores\, \page\, \navigating\, or \updated\ from this path now throws an error. Users must migrate to the new \$app/state\ module, which provides these values as modern Svelte stores (or state objects) and requires Svelte 5.
packages/kit/src/runtime/app · high confidence
Runtime components updated to Svelte 5 Runes mode
The internal runtime components (root, layout, error) have been rewritten to use Svelte 5's Runes syntax, replacing legacy Svelte 4 patterns with $props, $state, and $derived. This change ensures these core components are compiled in runes mode, aligning the framework's internal rendering logic with the newer Svelte API.
packages/kit/src/runtime/components · high confidence
Standardized diagnostic error messages with consistent URLs
The internal error handling system has been refactored to standardize how SvelteKit diagnostics are formatted and displayed. All build, server, and client errors now follow a uniform structure: a specific error code, a descriptive message, and a link to the documentation (https://svelte.dev/e/kit/{code}). This change ensures that developers receive consistent, actionable feedback across different parts of the framework, whether during build time, server-side execution, or client-side runtime. The refactoring also introduces better support for stack trace management and error capturing, improving the debugging experience by providing clearer context for errors.
packages/kit/src/messages/internal · high confidence
Standardized error and warning message templates
The message generation templates for build, client, server, and shared contexts have been updated to consistently include the error code URL (https://svelte.dev/e/kit/CODE) in console output. In production, warnings and errors now log this URL directly, while development mode retains the full formatted message alongside the URL, ensuring users can always access detailed documentation for specific diagnostic codes.
packages/kit/scripts/process-messages/templates · high confidence
Standardized error and warning messages with dedicated documentation links
SvelteKit now provides a comprehensive, standardized set of error and warning messages across build, client, server, and shared contexts. These messages are generated from a central source and include specific guidance for common issues, such as deprecated options (e.g., \invalidateAll\ replaced by \refreshAll\), configuration errors, and runtime warnings. Each message now includes a unique URL (e.g., \https://svelte.dev/e/kit/...\) that links directly to detailed documentation, helping users resolve issues more quickly. This change affects how users see and interpret errors and warnings in both development and production environments.
packages/kit/src/messages · high confidence
Stricter external redirect validation and new reroute helper
Redirects to external URLs are now forbidden by default; you must explicitly pass \{ external: true }\ or an allowlist of permitted origins to bypass this check, and attempts to redirect to \javascript:\ URLs are blocked even when external redirects are enabled. Additionally, a new \applyReroute\ helper is exported to allow catch-all serverless handlers to process the \reroute\ hook and invoke the correct handler for rewritten URLs.
packages/kit/src/exports · high confidence
Svelte package tooling is restructured and upgraded to Node 22
The \@sveltejs/package\ functionality has been extracted into its own standalone package, requiring Node 22 or newer. The CLI now reads the Svelte configuration via \@sveltejs/load-config\ and warns if \config.package\ is used, directing users to migrate. Import aliases are now transformed into relative imports in the output files, and the tool warns when \.server.\ files or files inside a \server\ directory are used without importing a server-only module. Additionally, the \svelte-package\ command now supports a \--preserve-output\ flag to prevent deletion of the output directory before packaging, and it correctly handles TypeScript declarations when the \tsconfig\ lives above the package root.
packages/package · high confidence
SvelteKit 3.0.0 release with major breaking changes and new features
SvelteKit 3.0.0 is now available, introducing significant breaking changes and new capabilities. Key updates include requiring Node 22.17 and TypeScript 6, upgrading to Vite 8, and moving many types to dedicated modules like $app/server, $app/state, and $app/navigation. The $lib alias is replaced with \#lib, and server-only directories are now strictly enforced. New features include support for function validators for environment variables, shallow routing, and sourcemaps in production. The $app/stores module is removed, and form actions now use HTTP status codes from fail().
packages/kit · high confidence
Updated Vercel adapter serverless functions to use standard fetch API and handle ISR pathnames
The adapter-vercel files now implement serverless functions using the standard Web \fetch\ export instead of previous Node-specific entry points. The serverless handler includes logic to decode ISR (Incremental Static Regeneration) requests by extracting the original pathname from the \\_\_pathname\ search parameter, ensuring correct routing for cached pages. Additionally, a new catch-all function is introduced that applies rerouting via the \applyReroute\ helper, supporting Vercel's middleware rewrite capabilities.
packages/adapter-vercel/files · high confidence
adapter-auto v8 requires SvelteKit 3 and adds Render support
The adapter-auto package now requires SvelteKit 3 as a peer dependency, marking a major version break from previous versions. It also introduces zero-config deployment support for the Render platform by detecting the RENDER environment variable and installing @sveltejs/adapter-node. Additionally, the package now correctly handles Windows paths by converting resolved adapter paths to file URLs before importing, and allows prerelease versions of SvelteKit 3 to satisfy the peer dependency range.
packages/adapter-auto · high confidence
adapter-cloudflare v8.0.0: Breaking changes for SvelteKit 3 and Wrangler 4
The Cloudflare adapter has been updated to version 8.0.0, introducing several breaking changes required for SvelteKit 3 and Wrangler 4. Users must now use Wrangler version 4.118.0 or higher and upgrade the \@cloudflare/workers-types\ package. The adapter no longer uses the legacy Cloudflare Workers Cache API, switching instead to Workers Caching, and has removed the deprecated \platform.context\ property in favor of \platform.ctx\. Additionally, the adapter now emulates the \cloudflare:workers\ module directly rather than exposing a Cloudflare platform object, and the build process has replaced \builder.generateManifest\ with \builder.generateServerInstance\ and \builder.manifest\. The adapter also now requires SvelteKit 3 and validates that \\_routes.json\ is not present in the static directory, enforcing configuration via the adapter options instead.
packages/adapter-cloudflare · high confidence
adapter-netlify v7.0.0: Migration to Netlify Frameworks API and SvelteKit 3
The Netlify adapter has been updated to version 7.0.0, introducing several breaking changes. It now writes build output conforming to the stable Netlify Frameworks API, which requires upgrading the Netlify CLI to v17.31.0 or later. The adapter now requires SvelteKit 3 and Vite 8 (specifically ^8.0.12), and static files are written based on the new \publish\ adapter option rather than reading \netlify.toml\. Additionally, edge function bundling has switched to \rolldown\ with a build target of \es2022\, and the internal manifest generation API has changed from \builder.generateManifest\ to \builder.generateServerInstance\ and \builder.manifest\. The adapter also supports combining \split\ and \edge\ options and uses \node:fs\ instead of deprecated builder helpers.
packages/adapter-netlify · high confidence
adapter-node v6.0.0 requires SvelteKit 3 and Vite 8, migrating to rolldown
The adapter-node package has been updated to version 6.0.0, which introduces several breaking changes and requires SvelteKit 3 and Vite 8 (specifically ^8.0.12). The build system has migrated from rollup to rolldown, and the adapter now records static assets at build time, serving them only to GET and HEAD requests with content-hash ETags instead of Last-Modified headers. The \ORIGIN\ environment variable has been removed in favor of the \kit.paths.origin\ config option, and the \builder.generateManifest\ API has been replaced by \builder.generateServerInstance\ and \builder.manifest\. Additionally, the adapter no longer uses polka, attaching the handler directly to the HTTP server, and it bundles the server source directly rather than prebuilding it.
packages/adapter-node · high confidence
adapter-static v4.0.0 requires SvelteKit 3 and fixes Vercel caching and redirect handling
The adapter-static package has been updated to version 4.0.0, which introduces a breaking change by requiring SvelteKit 3 as a peer dependency. This release includes several important fixes for Vercel deployments: it prevents immutable assets from being cached when they return 404s, and it aligns the handling of prerendered redirects with the adapter-vercel implementation. Additionally, the adapter now uses \node:fs\ for file operations instead of deprecated builder methods and accesses configuration via \builder.config\.
packages/adapter-static · high confidence
adapter-vercel v7.0.0: Major runtime and bundling overhaul
The Vercel adapter has been updated to version 7.0.0, introducing several breaking changes for users. Edge runtime support has been removed, and the adapter now exclusively supports Node.js 22, Node.js 24, and Bun 1.x runtimes. For bundling edge functions, the adapter has switched from esbuild to Rolldown, with the build target raised to ES2022. This change also requires Vite 8.0.12 or later. Additionally, the adapter's instrumentation API has been updated to populate environment variables before \instrumentation.server.js\ is evaluated, and the internal manifest generation API has been replaced with \builder.generateServerInstance\ and \builder.manifest\. Several bug fixes are included, such as correcting ISR pathname handling with trailing slashes and preventing race conditions in initialization.
packages/adapter-vercel · high confidence
Fixes
Fix prerender URL crawling for base paths, srcset, and invalid schemes
The prerendering process now correctly resolves relative URLs against a \<base\> tag, handles srcset attributes containing newlines after commas, and properly ignores empty image sources. It also adds support for crawling URLs found in specific meta tags (like og:image) and correctly identifies non-HTTP URL schemes (such as at://) as invalid during the crawl, ensuring they are reported rather than causing errors or incorrect resource inclusion.
packages/kit/src/core/postbuild/fixtures · high confidence
Test coverage
Add Playwright test configuration for Cloudflare adapter; Add basic Vercel adapter test application; Add prerendering basics test suite; Add test infrastructure and configuration for the basics app; Add test-redirect-importer package to validate SvelteKit redirect imports; Added CSRF test route for HTTP method coverage; Added Playwright integration tests for image rendering; Added Playwright test configuration for adapter-node; Added Playwright tests for SPA adapter fallback and prerendering behavior; Added Playwright tests for Vercel adapter functionality; Added Playwright tests for hash-based routing; Added Playwright tests for remote functions and forms in the async test app; Added XSS test routes for query parameters, dynamic paths, and script injection; Added accessibility test routes for focus management and form submission; Added async test app with remote function transport and error handling hooks; Added async test app with unit tests for build stability and sourcemaps; Added basic test application for the Bun adapter; Added basic test suite for the Vercel adapter; Added build-error tests for private env, prerendering, and service worker imports; Added cookie handling test routes; Added dev-only test app for server-only module and dependency optimization tests; Added integration test app for Netlify edge adapter; Added integration test app for Netlify split functions; Added integration test infrastructure for enhanced-img; Added integration tests for Netlify split functions adapter; Added integration tests for adapter-node; Added integration tests for basic adapter functionality; Added integration tests for the Netlify adapter's split function mode; Added prerendering tests for fetch endpoint buffering behavior; Added static test assets for symlink and special character handling; Added static test assets for the Node adapter; Added syntax-error test app to verify build error detection; Added test app entry points for fetch cache control scenarios; Added test app for Cloudflare Pages adapter server-side dependency resolution; Added test app for Cloudflare Workers adapter; Added test app for SPA (no-SSR) mode; Added test app for SPA mode in adapter-static; Added test app for SvelteKit options; Added test app for Vercel split platform configuration; Added test app for anchor navigation scenarios; Added test app for asset import functionality; Added test app for embedded mode; Added test app for enhanced form submissions with non-ActionResult responses; Added test app for filesystem write and HMR behavior; Added test app for forced route invalidation; Added test app for form action enhancements; Added test app for inline bundle strategy and custom type serialization; Added test app for invalidate/reroute behavior; Added test app for multiple invalidation scenarios; Added test app for preload-code attribute scenarios; Added test app for prerendered error pages; Added test app for private service worker environment variable access; Added test app for remote functions and forms; Added test app for the \read\ API; Added test app route components for async testing; Added test app routes for SPA adapter testing; Added test app routes to verify error pages, layout loading, and route ID access; Added test app setup for adapter-node environment variable handling; Added test apps for private environment variable handling; Added test case for prerendering with shadowed POST actions; Added test case for remote function usage without experimental flag; Added test cases for server data reuse scenarios; Added test coverage for CSS import handling and specificity; Added test coverage for action redirects with form enhancement; Added test coverage for base path prerendering; Added test coverage for base64-serialized fetch body caching; Added test coverage for client-side build omission in no-CSR mode; Added test coverage for content negotiation routing; Added test coverage for custom identifier invalidation on goto(); Added test coverage for fetch request headers in load functions; Added test coverage for fetch response header filtering; Added test coverage for forced navigation invalidation; Added test coverage for form target blank behavior; Added test coverage for handling HTTP 204 responses with no body; Added test coverage for hash link focus behavior; Added test coverage for importing Web Workers via URL; Added test coverage for load function dependency invalidation; Added test coverage for mutative endpoints with form actions; Added test coverage for navigation event exposure; Added test coverage for navigation with hash links under a base element; Added test coverage for no-SSR routing and configuration; Added test coverage for preloadData with reroute scenarios; Added test coverage for prerendering in non-ASCII routes; Added test coverage for prerendering with origin context; Added test coverage for relative path resolution during prerendering; Added test coverage for repeated data-sveltekit-preload-data links; Added test coverage for serialization of empty load nodes; Added test coverage for server node analysis environment variable handling; Added test coverage for server-only load functions returning non-JSON data; Added test coverage for server-side fetch abort signal handling; Added test coverage for streamed custom type serialization; Added test coverage for trailing slash handling in server-side data requests; Added test coverage for typed params prop in layout and page components; Added test fixture for Cloudflare Workers config path resolution; Added test fixture for hash link focus behavior; Added test fixture for hash-based routing and focus management; Added test fixture for prerendered image fetching; Added test fixture for prerendering options; Added test fixture for prerendering with base path; Added test fixtures for cache-control behavior; Added test fixtures for compression and instrumentation; Added test fixtures for nested layout and error handling; Added test fixtures for no-server-load route scenarios; Added test fixtures for preload-data target route; Added test fixtures for prerendered route and endpoint behavior; Added test fixtures for prerendered trailing slash behavior; Added test fixtures for prerendering asset handling; Added test fixtures for prerendering options; Added test fixtures for prerendering with .html route directories; Added test fixtures for prerendering with server-side data loading; Added test fixtures for remote module re-export scenarios; Added test fixtures for route parameter invalidation; Added test fixtures for routing cancellation scenarios; Added test fixtures for server endpoint behaviors; Added test for $app/state module usage in prerendered routes; Added test for ArrayBuffer handling in load functions; Added test for CSS handling in routes with special characters; Added test for POST fetch with body in load data; Added test for POST request serialization in load function; Added test for URL immutability and goto mutation handling; Added test for URL mutation resilience in load context; Added test for URL query parameter handling in load functions; Added test for adjacent error boundary handling in form actions; Added test for batched synchronous invalidation; Added test for beforeNavigate complete promise on redirect; Added test for circular dynamic imports; Added test for content-length header generation; Added test for detecting missing IDs during prerendering; Added test for dynamically imported CSS in Svelte components; Added test for dynamically imported component styles; Added test for empty headers in fetch Request serialization; Added test for external fetch cookie forwarding behavior; Added test for fetch cache control with differing headers; Added test for fetch response body streaming; Added test for fetching assets via load function; Added test for fetching the same URL multiple times; Added test for file uploads without multipart encoding; Added test for focus retention during navigation; Added test for form controls shadowing nodeName; Added test for form error field persistence with deserialized data; Added test for form error hydration; Added test for immutable response headers during prerendering; Added test for invalidation-then-goto scenario; Added test for malicious cache-control header injection; Added test for navigation callback cleanup; Added test for navigation with missing href; Added test for non-ASCII route paths in prerendering; Added test for non-canonical external fetch caching; Added test for preloadCode during initial page load; Added test for prerender failure on remote function error; Added test for prerenderable route not being prerendered; Added test for prerendering hash links with non-ASCII characters; Added test for prerendering with SSR disabled; Added test for redirect behavior with dynamic paths in paths-base prerendering; Added test for server load data serialization in load functions; Added test for server-guard handling of shared server-only modules; Added test for server-side external redirects; Added test for server-side response cloning in load functions; Added test for server-side search param logging; Added test for static environment variable handling in prerendering; Added test harness for Cloudflare Workers adapter; Added test infrastructure for the prerendered adapter-static app; Added test mocks for SvelteKit internal modules; Added test page for SPA fallback rendering with public env vars; Added test page for app environment version exposure; Added test page for data-sveltekit preload attributes; Added test page for element toggling interactivity; Added test page for external popstate handling; Added test page for form action handling; Added test page for grouped prerender routes; Added test page for hash routing and preload behavior; Added test page for hash-based routing in route 'b'; Added test page for long navigation scenarios; Added test page for navigation prevention logic; Added test page for onNavigate lifecycle; Added test page for optional route parameters; Added test page for public environment variables in prerendered app; Added test page for remote library integration; Added test page for scroll-to-top behavior; Added test pages for cross-document scroll behavior; Added test pages for fork route shallow routing and parameter handling; Added test pages for navigation lifecycle scenarios; Added test pages for reroute error handling and external navigation; Added test pages for shallow routing and state management; Added test pages for the afterNavigate lifecycle hook; Added test route for \invalidateAll\ bypass in form enhancement; Added test route for disabling client-side rendering; Added test route for focus reset behavior; Added test route for form action success data handling; Added test route for non-enhanced form serialization; Added test route for remote module resolution in plain-lib; Added test route for server data no-store behavior; Added test routes for $app/state integration and routing edge cases; Added test routes for REST parameter handling and dynamic path rendering; Added test routes for URL encoding and special characters; Added test routes for URL hash and toString behavior; Added test routes for \$app/state\ data handling; Added test routes for accumulated load data; Added test routes for adapter platform context; Added test routes for external redirect scenarios; Added test routes for goto navigation scenarios; Added test routes for headers and cookies; Added test routes for load caching behavior; Added test routes for load function behavior; Added test routes for offline data preloading scenarios; Added test routes for preloading error handling, redirects, and hash-based state; Added test routes for redirect behavior; Added test routes for routing scenarios; Added test routes for server-side error boundary behavior; Added test routes for shadowed hydration scenarios; Added test routes for snapshot functionality; Added test routes for static adapter and Kit routing scenarios; Added test routes for the \untrack\ function in load functions; Added test suite for SPA mode in adapter-static; Added test suite for adapter-node build output; Added test to verify adapter version consistency; Added test utilities for Netlify adapter integration tests; Added tests for ArrayBufferView request body types; Added tests for POST body serialization in load functions; Added tests for SPA shell prerendering behavior; Added tests for URL search parameter invalidation; Added tests for basic reroute hook behavior; Added tests for client-side trailing slash redirect behavior; Added tests for data-sveltekit-replacestate link behavior; Added tests for dynamic route parameter type generation; Added tests for environment variable access routes; Added tests for ignored file handling; Added tests for immutable headers handling; Added tests for invalidating implicit dependencies in server load functions; Added tests for load change detection and invalidation; Added tests for load invalidation during navigation; Added tests for optional route parameter type generation; Added tests for param type inference with matchers and parsing; Added tests for parent data loading in nested layouts; Added tests for prerender origin crawling behavior; Added tests for prerendered app behavior; Added tests for prerendered endpoint behavior in handle hooks and parameterized routes; Added tests for prerendered paths-base app; Added tests for prerendering URL encoding and path handling; Added tests for prerendering options and CSP handling; Added tests for prerendering with SSR disabled; Added tests for removed $lib and $service-worker imports; Added tests for route parameter matching and bigint support; Added tests for scroll state in navigation lifecycle hooks; Added tests for search parameter invalidation behavior; Added tests for server-only module import restrictions; Added tests for server-only module resolution in nested directories; Added tests for server-side fetch origin header handling; Added tests for strongly typed form submission results; Added tests for the $app/manifest module; Added tests for the $app/state navigating store; Added tests for the \data-sveltekit-reset\ attribute behavior; Added tests for the new $app/state module; Added tests for the new match function in $app/paths; Added tests for trailingSlash option on pages and endpoints; Added tests for window.fetch patching in load functions; Added type tests for actions, error handling, remote functions, and environment variables; Added type-generation tests for layout and page load data; Added type-generation tests for nested layout and page data inheritance; Added type-generation tests for server-only pages and nested layouts; Added type-generation tests for slug parameter handling in layouts; Expanded E2E test coverage for client-side navigation, accessibility, and server behavior; Expanded error handling test suite in the basics app; Expanded test coverage for SvelteKit routing, data loading, and prerendering; Expanded test samples for route manifest generation; Expanded test suite for SvelteKit core features; Expanded type tests for route IDs, matchers, and trailing slash configurations; New test app for Kit options and configuration; New test infrastructure and diagnostic matchers; Standardized Playwright test configuration for adapter-static; Updated test fixtures to use centralized param definitions.
Dependencies
2554 commits updating dependencies (96 manifests)
A dependency / build maintenance change in (dependencies) — 2554 commits (221 fixs), 96 files.
(dependencies) · high confidence · unverified
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 67 → 64 (-2.7)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 71 → 72 (+0.8)
- Architecture 91 → 92 (+1.1)
- Maturity 65 → 65 (-0.2)
- Readiness 71 → 70 (-0.6)
- Security 69 → 77 (+8.5)
- Accessibility 64 → 64 (+0.0)
- Performance 60 (new)
Resolved (35)
- (anonymous)::adapt (cognitive 27) (packages/adapter-bun/index.js)
- (anonymous)::adapt (cyclomatic 22) (packages/adapter-bun/index.js)
- Boundary-crossing change coupling: index.js ↔ fallback.js (packages/adapter-node/index.js)
- Documentation: contradicts the code (documentation/docs/index.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: packages/adapter-cloudflare/utils.js (packages/adapter-cloudflare/utils.js)
- Hotspot: packages/enhanced-img/src/vite-plugin.js (packages/enhanced-img/src/vite-plugin.js)
- Hotspot: packages/kit/src/exports/vite/plugins/remote.js (packages/kit/src/exports/vite/plugins/remote.js)
- Hotspot: packages/kit/src/exports/vite/static_analysis/index.js (packages/kit/src/exports/vite/static_analysis/index.js)
- Hotspot: packages/kit/src/runtime/server/index.js (packages/kit/src/runtime/server/index.js)
- Hotspot: packages/kit/src/runtime/shared.js (packages/kit/src/runtime/shared.js)
- Hotspot: packages/package/src/index.js (packages/package/src/index.js)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Outdated (npm): @vercel/nft
- …and 15 more
New (31)
- (anonymous)::adapt (cognitive 19) (packages/adapter-bun/index.js)
- (anonymous)::adapt (cyclomatic 16) (packages/adapter-bun/index.js)
- Change coupling: fallback.js ↔ index.js (packages/kit/src/core/postbuild/fallback.js)
- FunctionTooLong: prerender.prerender (packages/kit/src/core/postbuild/prerender.js)
- Hotspot: packages/adapter-node/src/static.js (packages/adapter-node/src/static.js)
- Medium: security finding (details withheld)
- No assertions: allows %j with %j (packages/kit/src/exports/url.spec.js)
- No assertions: distinct keyed form instances can attach independently (packages/kit/src/runtime/client/remote-functions/form.svelte.spec.js)
- Off-boarding risk: anonymized user #1
- Outdated (npm): jsdom
- Repeated repair: packages/kit/test/apps/async/test/test.js (packages/kit/test/apps/async/test/test.js)
- Repeated repair: packages/kit/test/apps/options/test/test.js (packages/kit/test/apps/options/test/test.js)
- Skipped (documented): (unnamed test) (packages/adapter-bun/test/apps/basic/test/server.test.js)
- Skipped (documented): (unnamed test) (packages/kit/test/apps/async/test/server.test.js)
- Skipped (documented): (unnamed test) (packages/kit/test/apps/async/test/server.test.js)
- Skipped (documented): (unnamed test) (packages/kit/test/apps/basics/test/playwright/cross-platform/server.test.js)
- Split packages/kit
- analyse (cognitive 41) (packages/kit/src/core/postbuild/analyse.js)
- analyse (cyclomatic 28) (packages/kit/src/core/postbuild/analyse.js)
- client.setup_preload (cyclomatic 30) (packages/kit/src/runtime/client/client.js)
- …and 11 more
Changes since last survey
- 103 commits — 61 feature/other, 42 fixes
By area
- packages/kit — 52 commits
- documentation/docs — 11 commits
- .github/workflows — 8 commits
- .changeset/pre — 6 commits
- (root) — 5 commits
- (repo) — 4 commits
- packages/adapter-node — 4 commits
- .github/actions — 2 commits
- .changeset/brave-types-start.md — 1 commit
- .changeset/calm-files-compress.md — 1 commit
- .changeset/changelog.js — 1 commit
- .changeset/drop-scroll-restoration-reset.md — 1 commit
- .changeset/pretty-shrimps-write.md — 1 commit
- .changeset/restore-bfcache-scroll.md — 1 commit
- .changeset/tidy-crawlers-stop.md — 1 commit
- packages/adapter-bun — 1 commit
- packages/adapter-cloudflare — 1 commit
- packages/adapter-netlify — 1 commit
- packages/adapter-static — 1 commit
Notable commits
- fix: Revert "fix: preserve untouched selects during remote form validation" (#17184)
- fix: chore: add missing adapter-bun LICENSE, fix single-file test command in AGENTS.md (#17199)
- fix: chore: fix and simplify the platform tests (#17171)
- fix: chore: fix link (#17299)
- fix: chore: fix platform workflows (#17152)
- fix: chore: fix server fetch test setup (#17290)
- fix: chore: platform test fixes (#17157)
- fix: fix links (#17289)
- fix: fix: bundle dev deps (#17210)
- fix: fix: catalog missing route file prefix warning (#17288)
- fix: fix: clear navigating when a shallow popstate aborts an in-flight navigation (#17118)
- fix: fix: dispose the platform proxy when the Vite dev or preview server closes (#17238)
- fix: fix: enforce request body size limits when Content-Type is absent (#17127)
- fix: fix: evict hashed fetch cache entries after mutations (#17146)
- fix: fix: exit build workers after completing their tasks while allowing synchronous exit handlers to run (#17135)
- fix: fix: generate a never Path type when there are no routes (#17228)
- fix: fix: generate types on dev server startup (#17034)
- fix: fix: handle failed production link preloads (#17181)
- fix: fix: ignore nested outDir files outside generated (#17150)
- fix: fix: keep a form.for instance registered across derived reconnection (#17230)
- …and 83 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sveltejs/kit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 585ebed0b2b9ee118ed0a2478de7ed38ad3e90c6 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.