Skip to content

breaking: remove leading / from AssetPath and Path - #16430

Merged
Rich-Harris merged 18 commits into
version-3from
slashless-assets-and-paths
Jul 20, 2026
Merged

Rich-Harris merged 18 commits into
version-3from
slashless-assets-and-paths

Conversation

@Rich-Harris

@Rich-Harris Rich-Harris commented Jul 19, 2026 •

Copy link
Copy Markdown
Member

While working on #16372 I had a realisation that we shouldn't prefix Asset and Pathname strings with a /. It makes no sense — these are intended to be relative to the base path, and so having them be root-relative (/favicon.png instead of favicon.png) is wrong.

This change means Pathname is the wrong name, since it wrongly implies a root-relative url.pathname. As well as removing the leading slash this PR renames Pathname to Path, and Asset to AssetPath. (This allows future us to add a new Asset type containing path: AssetPath, and possibly other stuff like type and size.)

There are practical benefits to removing the leading slash:

  • In feat: add $app/manifest module #16372, we're adding an $app/manifest module with immutable and assets exports. The latter is an array of objects with a path property — rather than typing it as string, we can type it as AssetPath. But if it had a leading slash then it would be unsuitable for its main purpose, which is for use with cache.add(path) inside a service worker. We can either make it base-path-relative (as this PR proposes) or root-relative (i.e. /my-basepath/favicon.png) which is inherently less portable.
  • Similarly, we can type the path elements in the prerendered array as Path rather than string
  • We can more easily distinguish between resolve(path) and resolve(route_id), both type-wise and at runtime. At the moment they're sort of smushed together awkwardly

I also think that asset('favicon.png') is just nicer to look at than asset('/favicon.png') which is either weird or pointless depending on whether there's a configured base.

Anyway: this is all somewhat independent of the $app/manifest stuff so I figured it deserved its own PR.

Closes #16425, by tightening up the type of AssetPath (no string & {}).


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 19, 2026 •

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from 9956b0a:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/9956b0a3f9a410f71f28ed94e6dd9deff8a51cb4

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16430

@changeset-bot

changeset-bot Bot commented Jul 19, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9956b0a

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Major

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@svelte-docs-bot

Copy link
Copy Markdown

Comment thread packages/kit/src/runtime/app/paths/server.js
Rich-Harris and others added 3 commits July 19, 2026 17:51
…lash-prefixed pathnames because `resolve_route` is always called even for relative (non route-ID) inputs.

This commit fixes the issue reported at packages/kit/src/runtime/app/paths/server.js:24

## Bug

In `packages/kit/src/runtime/app/paths/server.js`, `resolve(id, params)` unconditionally calls `resolve_route(id, params ?? {})`, regardless of whether `id` starts with `/`.

`resolve_route` → `get_route_segments` does `route.slice(1)`:

```js
export function get_route_segments(route) {
	return route.slice(1).split('/').filter(affects_path);
}
```

That `slice(1)` assumes the input is a route ID with a leading slash. When a plain pathname without a leading `/` is passed, the first character is silently dropped:

*   `resolve_route('favicon.png', {})` → `/avicon.png`
*   `resolve_route('about/us', {})` → `/bout/us`
*   `resolve_route('/about', {})` → `/about` (correct)

Because this PR makes `AssetPath`/`Path` relative (no leading `/`), `resolve` now regularly receives non-slash inputs. This is especially impactful for `asset()`: in the default config `assets === base === ''`, so `asset('favicon.png')` calls `resolve('favicon.png')` and returns the corrupted `/avicon.png`.

The client implementation (`client.js`) is correct — it only calls `resolve_route` for `/`-prefixed route IDs and otherwise returns `base + pathname_prefix + '/' + args[0]`. The server version was missing the equivalent branch.

## Fix

Mirror the client's branching in the server `resolve`:

```js
let resolved;

if (id[0] === '/') {
	if (id.includes('[') && !params) {
		throw new Error(`Missing params for dynamic route ID  
```

The existing `relative`/`base` handling continues to operate on `resolved`, so no other behavior changes. Now `asset('favicon.png')` resolves to `/favicon.png` (or the appropriate relative/base-prefixed form) instead of `/avicon.png`.


Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Rich-Harris <hello@rich-harris.dev>
Comment thread packages/kit/src/runtime/app/paths/server.js Outdated
… the resolved URL for static route IDs with no params, diverging from the client.

This commit fixes the issue reported at packages/kit/src/runtime/app/paths/server.js:34

## Bug

In `packages/kit/src/runtime/app/paths/server.js`, the `/`-prefixed branch was changed to:

```js
resolved = params ? resolve_route(id, params) : id;
```

When `params` is falsy (i.e. a static route ID passed with no params), this skips `resolve_route` entirely and uses the raw route `id`. But `resolve_route` → `get_route_segments` → `affects_path` also strips layout **group** segments matching `/^([^)]+)$/` (e.g. `(app)`, `(marketing)`), not just dynamic params.

### Concrete triggers
- `resolve('/(app)/dashboard')` returns `/(app)/dashboard` (literal parens in the URL) instead of `/dashboard`.
- `resolve('/(marketing)')` returns `/(marketing)` instead of `/`.

`resolve_route('/(app)/dashboard', {})` correctly returns `/dashboard`, confirming the divergence.

### Client/server parity
The client implementation (`client.js`) always calls `resolve_route(args[0], args[1] ?? {})` for `/`-prefixed inputs, so it correctly strips groups. The server change caused a mismatch: any static route inside a layout group would render broken links on the server.

## Fix

Restore unconditional group-stripping by always calling `resolve_route`, matching the client:

```js
resolved = resolve_route(id, params ?? {});
```

This handles both static routes with group segments and dynamic routes, and restores client/server parity.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Rich-Harris <hello@rich-harris.dev>
Comment thread documentation/docs/98-reference/20-$app-types.md Outdated
Co-authored-by: Tee Ming <chewteeming01@gmail.com>
@Rich-Harris Rich-Harris mentioned this pull request Jul 20, 2026
6 tasks done
@teemingc

teemingc commented Jul 20, 2026 •

Copy link
Copy Markdown
Member

Closes #16430, by tightening up the type of AssetPath (no string & {}).

This PR is 16430. Did you mean another issue?

Also, the test type check is erroring because we can no longer do the asset('') hack to get the asset base path

@Rich-Harris

Copy link
Copy Markdown
Member Author

Yep, I meant #16425. The check failure is annoying as I'd got rid of the red squigglies locally with /** @type {any} */ '', but apparently we need to be more invasive

Comment thread packages/kit/src/types/ambient.d.ts Outdated
Comment thread packages/kit/types/index.d.ts Outdated
Comment thread packages/kit/src/runtime/app/paths/types.d.ts Outdated
Comment on lines -25 to -27
if (pathname === '/') {
return [pathname];
}

@teemingc teemingc Jul 20, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we keep this check but return early on pathname === ''? Because the trailing slash handling below it doesn't make sense for the root page

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's already correct — previously the root would become '/', but now it becomes '' for trailingSlash = 'never', '/' for always, and '' | '/' for ignore, which I think is what we want. if we reinstated this and returned early it would always be ''

@teemingc teemingc Jul 20, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mm you're right about that. But this also causes ResolvedPathname to accept '//' right now. At

'\t\tResolvedPathname(): `${"/" | `/${string}/`}${ReturnType<AppTypes[\'Path\']>}`;',
it's formed by '/' plus the values of Path so we need to adjust that logic instead

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that's probably unavoidable, sadly, because of /${string}/. It's already like this today

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(but if there's a fix I'm missing we can always patch later)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah right. I'll just open an issue

@teemingc teemingc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Just one outstanding thought

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there no good way to share the logic between client and server here? Weird to have this specific pathname handling duplicated

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really, no. one uses shared global state, one needs AsyncLocalStorage. you could maybe try and tease bits of them apart to share implementations but it would end up looking worse I think

@Rich-Harris
Rich-Harris merged commit 2e71340 into version-3 Jul 20, 2026
35 of 36 checks passed
@Rich-Harris
Rich-Harris deleted the slashless-assets-and-paths branch July 20, 2026 17:14
Rich-Harris pushed a commit that referenced this pull request Jul 24, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/kit@3.0.0-next.12

### Major Changes

- breaking: rename `Pathname` type to `Path` and `Asset` to `AssetPath`
([#16430](#16430))
  breaking: remove leading `/` from `Path` and `AssetPath`
- breaking: write tsconfig to `node_modules/$app/tsconfig`
([#16458](#16458))

- breaking: error on `event.url`, `event.params` and `event.route`
access inside queries
([#16452](#16452))

- breaking: delete `$service-worker` module
([#16450](#16450))

- breaking: detect new deployments on data, remote, and form action
responses, tab focus, and visibility change, and default
`version.pollInterval` to 1 hour
([#16496](#16496))

### Minor Changes

- feat: add `$app/manifest` module with `immutable`, `assets`,
`prerendered`, and `routes` exports
([#16372](#16372))

- feat: validate that all remote form fields were created with
form.fields.foo.as(...)
([#16331](#16331))

- feat: make `$app/paths` importable in service workers
([#16441](#16441))

- feat: `$app/service-worker` module
([#16458](#16458))

- feat: better tsconfig validation
([#16458](#16458))

- fix: default cookies to `secure` to `false` during development
([#16462](#16462))

### Patch Changes

- fix: allow `undefined` values to be passed to form field `.as(...)`
where applicable ([#15681](#15681))

- fix: include queries refreshed from within another query in the
serialized response
([#16461](#16461))

- fix: generate sourcemaps for remote modules
([#16440](#16440))

- fix: avoid empty getElementById() call on hash routing navigation
([#16448](#16448))

- fix: warn if hook files are spelled as "hook" instead of "hooks"
([#16483](#16483))

- chore: deprecate the `alias` option
([#16470](#16470))

- fix: prevent infinite loops when server-side queries refresh each
other in a cycle during the single-flight drain
([#16461](#16461))

- fix: populate `version` in service workers
([#16434](#16434))

- fix: resolve remote modules as external during dev prebundling so
packages can re-export remote functions
([#16426](#16426))

- fix: refetch route-tracking server data when navigating away from an
error page ([#16381](#16381))

- fix: serialize `query(...).set(...)`/`query(...).refresh()` values
into the rendered HTML when called from within a query during SSR
([#16461](#16461))

- fix: fall back to the page's form actions when a sibling endpoint has
no POST handler ([#16349](#16349))

- fix: return a lightweight 404 instead of rendering the error page for
subresource requests
([#16463](#16463))

- fix: preserve stripped path prefixes by making trailing-slash
redirects relative
([#16431](#16431))

- chore: deduplicate type-stripping logic in `tweak_types`
([#16454](#16454))

- fix: more informative error message when running a command inside a
query or prerender function
([`eb5c973`](eb5c973))
## @sveltejs/adapter-cloudflare@8.0.0-next.3

### Patch Changes

- chore: bump `@cloudflare/workers-types` to `4.20260621.1`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-netlify@7.0.0-next.4

### Patch Changes

- fix: await `init` on every request to prevent race condition
([#16467](#16467))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-node@6.0.0-next.6

### Patch Changes

- fix: preserve stripped path prefixes by making trailing-slash
redirects relative
([#16431](#16431))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12
## @sveltejs/adapter-vercel@7.0.0-next.3

### Patch Changes

- fix: await `init` on every request to prevent race condition
([#16467](#16467))

- chore: bump Rolldown to `1.2.0`
([#16455](#16455))
- Updated dependencies
[[`adc4c5b`](adc4c5b),
[`ecb0701`](ecb0701),
[`4b4cc60`](4b4cc60),
[`7390dbe`](7390dbe),
[`2e71340`](2e71340),
[`c87bc3a`](c87bc3a),
[`af15c6c`](af15c6c),
[`c6fa431`](c6fa431),
[`bfe4dea`](bfe4dea),
[`df7dc72`](df7dc72),
[`5ae11a1`](5ae11a1),
[`781205c`](781205c),
[`c87bc3a`](c87bc3a),
[`a1bfeb9`](a1bfeb9),
[`c87bc3a`](c87bc3a),
[`9f0127d`](9f0127d),
[`4b4cc60`](4b4cc60),
[`8f5b9c7`](8f5b9c7),
[`c9b5544`](c9b5544),
[`fe1d4a4`](fe1d4a4),
[`4b4cc60`](4b4cc60),
[`5f78e95`](5f78e95),
[`25510fc`](25510fc),
[`c99a6cf`](c99a6cf),
[`17a45ca`](17a45ca),
[`2ca20c3`](2ca20c3),
[`eb5c973`](eb5c973)]:
  - @sveltejs/kit@3.0.0-next.12

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Rich-Harris added a commit that referenced this pull request Aug 4, 2026
…ams, several params in one segment, or escape sequences (#16577)

`/[[lang]]/about` generates the `Path` member `{string}/about`, a plain
string rather than a template: #16430 appended `.slice(1)` to a branch
whose replacement had already consumed the leading slash, chopping the
`$`. Since `resolve()` is bounded by `Path`, `resolve('en/about')` is
rejected while `resolve('{string}/about')` type checks.

The pathname is now built from the route's segments. An omitted optional
param contributes its own pathname instead of absorbing the following
`/`, so `xyzabout` is no longer admitted, and a second param in one
segment (`/[foo]-[bar]`) no longer leaks in verbatim.

Rest params get the same treatment, since `[...path]` can match zero
segments. Escape sequences are expanded the same way #16570 expands them
in `resolve`, so `/[x+2e]well-known` contributes `.well-known` rather
than the raw route id.

---------

Co-authored-by: Rich Harris <richard.a.harris@gmail.com>
Co-authored-by: Rich Harris <rich.harris@vercel.com>
@nickolay

nickolay commented Aug 20, 2026 •

Copy link
Copy Markdown

This change means Pathname is the wrong name, since it wrongly implies a root-relative url.pathname

Yet, resolve() still takes a PathnameWithSearchOrHash, makes multiple references to the pathname in its documentation, and conflicts with the standard definition of resolving relative references on the web.

It is also very weird that if you resolve a Path (without params, e.g. resolve('blog/hello-world');) you omit the leading slash, but if you resolve a RouteId (resolve('/blog/[slug]', {..}) you suddenly need it. Why doesn't the argument for "having them be root-relative (/favicon.png instead of favicon.png) [being] wrong" apply to the second form? (I know the technical answer now, but consider the user's perspective!)

Even worse, for simple routes you can use both, yet the migrator removes the leading / leading to unnecessary churn. For some reason it keeps resolve("/") alone though (update: sveltejs/cli#1268), which fails the type check when you have the root page in routes/(area)/+page.svelte. Trying to read the docs to figure what the heck is going on does not help at all: "Resolve a pathname by prefixing it with the base path, if any, or resolve a route ID by populating dynamic segments with parameters. During server rendering, the base path is relative and depends on the page currently being rendered" (I've highlighted the terms that make zero sense to someone who haven't already read the code.)

I also think that asset('favicon.png') is just nicer to look at than asset('/favicon.png')

Maybe, but what about <a href={resolve('')}> ? What about resolve('posts')?

The SK2 version might have been confusing to those who used the advanced functionality. The SK3 version, while technically superior, is confusing to those who don't know about base URL.

In case you're wondering why am I using resolve() at all — it's because eslint default set includes no-navigation-without-resolve. (That page needs an update explaining how SK2 and 3 are different in what they require the user to do...)


Anyway, what's the rush with requiring everyone to remove SK2-style pathnames from their resolve() calls? This PR is 1 month old, there have been no deprecations in SK2, and there's no way to prepare SK2 code so that the 2->3 migration doesn't have to change it all at once, which makes it harder to deal with branches — all for unclear gain.

@elliott-with-the-longest-name-on-github

Copy link
Copy Markdown
Contributor

@nickolay if you want to discuss this please open an issue! Merged PRs are not a good place to talk 😄

dadezzz added a commit to dadezzz/events-cash-register that referenced this pull request Oct 5, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@sveltejs/kit](https://svelte.dev) ([source](https://github.com/sveltejs/kit/tree/HEAD/packages/kit)) | [`2.70.3` → `3.0.0`](https://renovatebot.com/diffs/npm/@sveltejs%2fkit/2.70.3/3.0.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@sveltejs%2fkit/3.0.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@sveltejs%2fkit/2.70.3/3.0.0?slim=true) |

---

### Release Notes

<details>
<summary>sveltejs/kit (@&#8203;sveltejs/kit)</summary>

### [`v3.0.0`](https://github.com/sveltejs/kit/blob/HEAD/packages/kit/CHANGELOG.md#300)

[Compare Source](https://github.com/sveltejs/kit/compare/@sveltejs/kit@2.70.3...@sveltejs/kit@3.0.0)

##### Major Changes

- breaking: move remote function types to `$app/server` ([#&#8203;16740](sveltejs/kit#16740))

- breaking: remove `experimental.handleRenderingErrors` flag ([#&#8203;16265](sveltejs/kit#16265))

- breaking: make `getRequest` and `setResponse` synchronous ([#&#8203;16280](sveltejs/kit#16280))

- breaking: TypeScript 6 is now the minimum required version ([#&#8203;15930](sveltejs/kit#15930))

- breaking: refresh all load functions/queries when clicking a link to the current URL ([#&#8203;16572](sveltejs/kit#16572))

- breaking: move remote function types to `$app/server` ([#&#8203;16764](sveltejs/kit#16764))

- breaking: upgrade to `cookie` v2. Cookie names must now contain only ASCII characters ([#&#8203;13386](sveltejs/kit#13386))

- breaking: require Node 22 or newer ([#&#8203;12548](sveltejs/kit#12548))

- major: error when a client-requested single-flight mutation isn't respected by the server, allow the server to explicitly ignore refreshes ([#&#8203;16892](sveltejs/kit#16892))

- breaking: remove the `preloadStrategy` option. `modulepreload` will always be used ([#&#8203;15256](sveltejs/kit#15256))

- breaking: default the cookie `path` option to `'/'` ([#&#8203;15398](sveltejs/kit#15398))

- breaking: remove `@sveltejs/kit/node/polyfills` ([#&#8203;15430](sveltejs/kit#15430))

- breaking: add `config.kit.output.linkHeaderPreload` to preload using the `Link` header ([#&#8203;15939](sveltejs/kit#15939))

- breaking: require `@sveltejs/vite-plugin-svelte` v7 ([#&#8203;15371](sveltejs/kit#15371))

- breaking: make `page.url` immutable on a type level ([#&#8203;16256](sveltejs/kit#16256))

- breaking: remove `base`, `assets`, and `resolveRoute` from `$app/paths` ([#&#8203;15507](sveltejs/kit#15507))

- breaking: remove `createEntries` from the `Builder` object passed to adapter functions ([#&#8203;15509](sveltejs/kit#15509))

- breaking: return no content for 204 responses ([#&#8203;16200](sveltejs/kit#16200))

- breaking: rename `Pathname` type to `Path` and `Asset` to `AssetPath` ([#&#8203;16430](sveltejs/kit#16430))
  breaking: remove leading `/` from `Path` and `AssetPath`

- breaking: `handle`'s `resolve` is now typed to always return a `Promise` ([#&#8203;16352](sveltejs/kit#16352))

- breaking: remove `Server` constructor and `SSRManifest` from public types ([#&#8203;16876](sveltejs/kit#16876))

- breaking: require Svelte config options to be passed through the Vite plugin ([#&#8203;16007](sveltejs/kit#16007))

- breaking: form action responses now use the HTTP status code returned from `fail` ([#&#8203;16200](sveltejs/kit#16200))

- breaking: write tsconfig to `node_modules/$app/tsconfig` ([#&#8203;16458](sveltejs/kit#16458))

- breaking: move `defineParams` and associated types to `@sveltejs/kit/params` ([#&#8203;16716](sveltejs/kit#16716))

- breaking: remove the deprecated CSRF `checkOrigin` option in favor of `trustedOrigins` ([#&#8203;15437](sveltejs/kit#15437))

- breaking: the `delta` property now only exists for `popstate` navigation events ([#&#8203;15522](sveltejs/kit#15522))

- breaking: change `form.error` type from `any` to `App.Error | undefined` ([#&#8203;16245](sveltejs/kit#16245))

- breaking: remove deprecated `pragma` header in version polling for improved CORS support ([#&#8203;15428](sveltejs/kit#15428))

- breaking: `goto` now rejects when called with a URL that does not resolve to a route within the app, matching the existing behaviour for external URLs ([#&#8203;16164](sveltejs/kit#16164))

- breaking: run all errors through the `handleError` hook ([#&#8203;16664](sveltejs/kit#16664))

- breaking: require Svelte 5.56.4 or newer ([#&#8203;15371](sveltejs/kit#15371))

- breaking: error on `event.url`, `event.params` and `event.route` access inside queries ([#&#8203;16452](sveltejs/kit#16452))

- breaking: enhanced cross-page form actions now navigate to the action page on success and failure, matching native form behavior ([#&#8203;16684](sveltejs/kit#16684))

- breaking: delete `$service-worker` module ([#&#8203;16450](sveltejs/kit#16450))

- breaking: move `defineEnvVars` to `@sveltejs/kit/env` ([#&#8203;16375](sveltejs/kit#16375))

- breaking: nested server-only directories ([#&#8203;15685](sveltejs/kit#15685))

- feat: allow adapters to provide additional Vite plugins ([#&#8203;16206](sveltejs/kit#16206))

- breaking: replace the `$lib` alias with `#lib` and remove `files.lib` config. ([#&#8203;16360](sveltejs/kit#16360))

- breaking: remove `#lib` definition from `paths`; requires explicit module extensions as a result ([#&#8203;16736](sveltejs/kit#16736))

- chore: change `error`, `isHttpError`, `redirect`, and `isRedirect` to refer to public type instead of internal class ([#&#8203;13036](sveltejs/kit#13036))

- breaking: move hooks-related types to `@sveltejs/kit/hooks` ([#&#8203;16737](sveltejs/kit#16737))

- breaking: add 'error' result type to `preloadData` ([#&#8203;12579](sveltejs/kit#12579))

- breaking: detect new deployments on data, remote, and form action responses, tab focus, and visibility change, and default `version.pollInterval` to 1 hour ([#&#8203;16496](sveltejs/kit#16496))

- breaking: disallow cross-origin form submissions without a `Content-Type` header ([#&#8203;16347](sveltejs/kit#16347))

- breaking: Server-only directories (`/server/` in the path) are now treated as server-only everywhere inside the project (except `src/routes` and the assets directory) ([#&#8203;16360](sveltejs/kit#16360))

- breaking: `config` exported from a universal route file takes precedence over a server one ([#&#8203;16400](sveltejs/kit#16400))

- breaking: require Vite 8. Provides new functionality even for existing Vite 8 users such as faster builds with Vite hook filters and more powerful SvelteKit adapters with the Vite environment API ([#&#8203;15371](sveltejs/kit#15371))

- breaking: remove `data-sveltekit-*` option `'off'` in favour of `false` ([#&#8203;15907](sveltejs/kit#15907))

- breaking: move tracing out of the experimental namespace and remove the instrumentation flag ([#&#8203;16260](sveltejs/kit#16260))

- breaking: add `kit.paths.origin` config option, remove `kit.prerender.origin` and the `adapter-node` `ORIGIN` environment variable ([#&#8203;16161](sveltejs/kit#16161))

- breaking: move `Page`, `ReadonlyURL` and `ReadonlyURLSearchParams` from `@sveltejs/kit` to `$app/state` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: remove `$app/stores` ([#&#8203;15499](sveltejs/kit#15499))

- breaking: add `refreshAll` and deprecate `invalidateAll` ([#&#8203;16289](sveltejs/kit#16289))

- breaking: reject query parameters beginning with `x-sveltekit-` ([#&#8203;17125](sveltejs/kit#17125))

- breaking: disallow `*.remote.ts/js` files unless `experimental.remoteFunctions` is enabled ([#&#8203;16247](sveltejs/kit#16247))

- breaking: replace the `noScroll` and `keepFocus` options of `goto` with a single `reset` option, and the `data-sveltekit-noscroll` and `data-sveltekit-keepfocus` attributes with `data-sveltekit-reset` ([#&#8203;16558](sveltejs/kit#16558))

- breaking: don't abort navigation when calling `invalidate(All)` during navigation ([#&#8203;16188](sveltejs/kit#16188))

- breaking: consistent special filename patterns ([#&#8203;16382](sveltejs/kit#16382))

- breaking: allow `handleError` to influence status code ([#&#8203;16162](sveltejs/kit#16162))

- breaking: delegate CORS handling to Vite for static directory requests during development ([#&#8203;16357](sveltejs/kit#16357))

- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling stable `rolldown` 1.0.0 ([#&#8203;16134](sveltejs/kit#16134))

- breaking: only include routes with a `+page` or `+server` in `RouteId` ([#&#8203;16580](sveltejs/kit#16580))

- breaking: require Node 22.17 ([#&#8203;16597](sveltejs/kit#16597))

- breaking: deprecate `error(status, {...})` in favour of `error(status, message, {...})` ([#&#8203;16540](sveltejs/kit#16540))

- breaking: replace the `builder.generateManifest` with `builder.generateServerInstance` and `builder.manifest` ([#&#8203;16875](sveltejs/kit#16875))

- breaking: forbid external redirects by default ([#&#8203;16198](sveltejs/kit#16198))

- breaking: separate adapter Vite plugins into `pre` and `post` ([#&#8203;16711](sveltejs/kit#16711))

- breaking: remove param files in folder in favor of `params.js/ts` file ([#&#8203;16189](sveltejs/kit#16189))

- breaking: move env-related types to `@sveltejs/kit/env` ([#&#8203;16739](sveltejs/kit#16739))

- breaking: `preloadCode` now takes a route ID (e.g. `/blog/[slug]`) instead of a pathname. Route IDs are not prefixed with `paths.base` ([#&#8203;16576](sveltejs/kit#16576))

- breaking: move `BeforeNavigate`, `OnNavigate`, `AfterNavigate`, `Navigation`, `NavigationTarget`, `NavigationType`, `GotoOptions` and the `Navigation*` variant types from `@sveltejs/kit` to `$app/navigation` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: move `ActionResult` and `SubmitFunction` from `@sveltejs/kit` to `$app/forms` ([#&#8203;16694](sveltejs/kit#16694))

- breaking: remove `handleValidationError` and pass remote function validation errors to `handleError` with `kind: 'validation'` ([#&#8203;16672](sveltejs/kit#16672))

- breaking: remove deprecated `.run()` method from live queries ([#&#8203;16573](sveltejs/kit#16573))

##### Minor Changes

- feat: allow hyphens in param and matcher names ([#&#8203;16284](sveltejs/kit#16284))

- feat: add `$app/manifest` module with `immutable`, `assets`, `prerendered`, and `routes` exports ([#&#8203;16372](sveltejs/kit#16372))

- feat: ignore files with + prefix if they contain test/spec/stories ([#&#8203;16715](sveltejs/kit#16715))

- feat: add `ErrorProps` to generated types ([#&#8203;16272](sveltejs/kit#16272))

- feat: support sourcemaps in production ([#&#8203;16412](sveltejs/kit#16412))

- feat: return the list of compressed files from `builder.compress` ([#&#8203;16566](sveltejs/kit#16566))

- feat: better response logging ([#&#8203;16744](sveltejs/kit#16744))

- feat: warn when tsconfig doesn't exclude service worker ([#&#8203;16645](sveltejs/kit#16645))

- feat: validate that all remote form fields were created with form.fields.foo.as(...) ([#&#8203;16331](sveltejs/kit#16331))

- feat: support function validators for environment variables ([#&#8203;16402](sveltejs/kit#16402))

- feat: use `type: 'module'` for service worker registrations ([#&#8203;16169](sveltejs/kit#16169))

- feat: allow adapters to receive the Svelte config as a function argument when adding Vite plugins ([#&#8203;16986](sveltejs/kit#16986))

- feat: add shallow routing to `goto` and deprecate `pushState` and `replaceState` ([#&#8203;16449](sveltejs/kit#16449))

- feat: abort `request.signal` when the response closes prematurely, via a new `response` option for `getRequest` ([#&#8203;16793](sveltejs/kit#16793))

- feat: make `$app/paths` importable in service workers ([#&#8203;16441](sveltejs/kit#16441))

- feat: pass the project-relative source `filename` to the `preload` filter for fonts ([#&#8203;16443](sveltejs/kit#16443))

- feat: preserve page state set through `goto(..., { state, persistState: true })` across reloads ([#&#8203;16449](sveltejs/kit#16449))

- feat: reinstate `$env/static/private`, `$env/dynamic/private`, `$env/static/public`, `$env/dynamic/public` and `$app/environment` as deprecated aliases for `$app/env/private` `$app/env/public` and `$app/env` ([#&#8203;16334](sveltejs/kit#16334))

- feat: add `page` and `endpoint` booleans to `$app/manifest`'s `routes`, and export a `ManifestRoute` type ([#&#8203;16594](sveltejs/kit#16594))

- feat: `$app/service-worker` module ([#&#8203;16458](sveltejs/kit#16458))

- feat: resolve paths using the Vite config `root` option instead of `process.cwd()` to better support monorepo configurations such as Vitest workspaces ([#&#8203;15469](sveltejs/kit#15469))

- feat: better error logging ([#&#8203;16374](sveltejs/kit#16374))

- feat: add `PageRouteId` and `EndpointRouteId` to `$app/types` ([#&#8203;16594](sveltejs/kit#16594))

- feat: better tsconfig validation ([#&#8203;16458](sveltejs/kit#16458))

- feat: add `dirty()` property to form fields ([#&#8203;16208](sveltejs/kit#16208))

- feat: support the `QUERY` HTTP method in `+server.js` ([#&#8203;16782](sveltejs/kit#16782))

- feat: allow adapters to override `getRequest` and `setResponse` during `vite dev` and `vite preview` ([#&#8203;16753](sveltejs/kit#16753))

- chore: deprecate `Response` helpers in favor of platform-provided alternatives ([#&#8203;15448](sveltejs/kit#15448))

- feat: add `cookies.parse` method ([#&#8203;16203](sveltejs/kit#16203))

- chore: deprecate `export const snapshot` in favour of the `snapshot` helper ([#&#8203;16687](sveltejs/kit#16687))

- feat: add `snapshot` helper to `$app/navigation` ([#&#8203;16685](sveltejs/kit#16685))

- feat: support custom values in `page.state` via `transport` hook ([#&#8203;16662](sveltejs/kit#16662))

- fix: default cookies to `secure` to `false` during development ([#&#8203;16462](sveltejs/kit#16462))

- feat: warn when naively proxying requests that result in responses with a `content-encoding` header ([#&#8203;16633](sveltejs/kit#16633))

- feat: accept the checked state as a third argument to `.as('radio', ...)` and `.as('checkbox', ...)` so that these inputs reset to it after a submission ([#&#8203;16926](sveltejs/kit#16926))

- feat: add an `applyReroute` helper for adapters that support split serverless function deployments ([#&#8203;16665](sveltejs/kit#16665))

##### Patch Changes

- fix: prevent scheme-like path segments from causing off-site trailing-slash redirects ([#&#8203;17294](sveltejs/kit#17294))

- chore: share the action error result between form actions and remote forms ([#&#8203;16835](sveltejs/kit#16835))

- fix: persist global app state across module graph reloads ([#&#8203;16663](sveltejs/kit#16663))

- fix: generate valid `Path` types for routes with optional or rest params, several params in one segment, or escape sequences ([#&#8203;16577](sveltejs/kit#16577))

- fix: coerce values typed into remote form fields, and only apply the default given to `.as()` until the field is edited ([#&#8203;16939](sveltejs/kit#16939))

- fix: blur focused SVG elements before the DOM update on navigation ([#&#8203;16983](sveltejs/kit#16983))

- fix: support bigint params in server-side route resolution ([#&#8203;17130](sveltejs/kit#17130))

- chore: build streamed responses from async generators ([#&#8203;16847](sveltejs/kit#16847))

- fix: generate types when dev server starts ([#&#8203;17034](sveltejs/kit#17034))

- fix: allow `undefined` values to be passed to form field `.as(...)` where applicable ([#&#8203;15681](sveltejs/kit#15681))

- fix: respect `paths.relative` during development for client files ([#&#8203;17053](sveltejs/kit#17053))

- fix: validate prerender concurrency ([#&#8203;17145](sveltejs/kit#17145))

- chore: deprecate `builder.rimraf` and `builder.mkdirp` in favour of `node:fs` methods ([#&#8203;16610](sveltejs/kit#16610))

- fix: manipulate stack trace for errors that happen while generating prerender inputs ([#&#8203;17113](sveltejs/kit#17113))

- fix: don't treat callable standard schemas as function param matchers ([#&#8203;16403](sveltejs/kit#16403))

- fix: prevent non-redirect enhanced form results from navigating to another origin ([#&#8203;17293](sveltejs/kit#17293))

- fix: clarify circular imports from `src/env` ([#&#8203;17014](sveltejs/kit#17014))

- fix: keep memory flat when precompressing many files ([#&#8203;16993](sveltejs/kit#16993))

- fix: render remote form actions while prerendering ([#&#8203;17139](sveltejs/kit#17139))

- fix: ignore Vitest browser loader HTML transforms ([#&#8203;17092](sveltejs/kit#17092))

- fix: prevent failed link preloads from causing unhandled promise rejections in production ([#&#8203;17181](sveltejs/kit#17181))

- fix: resolve generated rootDirs from the project root ([#&#8203;17242](sveltejs/kit#17242))

- fix: generate route resolution modules as siblings of `.html` pages ([#&#8203;16674](sveltejs/kit#16674))

- perf: parse large streamed frames in linear time ([#&#8203;16489](sveltejs/kit#16489))

- fix: keep at most one pending body read at a time when deserializing binary forms ([#&#8203;16783](sveltejs/kit#16783))

- fix: escape cache-control headers in prerendered HTML ([#&#8203;17293](sveltejs/kit#17293))

- fix: decode all numeric character references, including above `ffff`, when crawling prerendered pages ([#&#8203;16611](sveltejs/kit#16611))

- fix: enforce request body size limits when Content-Type is absent ([#&#8203;17127](sveltejs/kit#17127))

- fix: include queries refreshed from within another query in the serialized response ([#&#8203;16461](sveltejs/kit#16461))

- fix: reject malformed streamed data encoding ([#&#8203;16423](sveltejs/kit#16423))

- perf: cache the default cookie header parse and avoid allocations in `cookies.get` ([#&#8203;16341](sveltejs/kit#16341))

- fix: exclude deleted cookies from `cookies.getAll()` so it stays consistent with `cookies.get()` ([#&#8203;16297](sveltejs/kit#16297))

- fix: hide stack traces for internal errors like 404s ([#&#8203;16411](sveltejs/kit#16411))

- chore: deduplicate repeated CSP directive handling ([#&#8203;16498](sveltejs/kit#16498))

- fix: render the nearest error page when a form submission receives a non-ActionResult error response ([#&#8203;16308](sveltejs/kit#16308))

- chore: bump `mrmime` to 2.0.1 ([#&#8203;16745](sveltejs/kit#16745))

- fix: correctly implement Vite plugin hook filters ([#&#8203;16760](sveltejs/kit#16760))

- fix: ignore nested outDir files outside generated ([#&#8203;17150](sveltejs/kit#17150))

- fix: defer `query.refresh()` in server commands until after the command body completes ([#&#8203;16225](sveltejs/kit#16225))

- fix: drain unconsumed request bodies so keep-alive connections don't hang ([#&#8203;16170](sveltejs/kit#16170))

- fix: keep `history.scrollRestoration` set to `manual` when leaving the page, so a document restored from the back/forward cache does not fall back to browser scroll restoration ([#&#8203;17244](sveltejs/kit#17244))

- fix: resolve service worker and `tsconfig.json` based on Vite `root` setting ([#&#8203;16229](sveltejs/kit#16229))

- fix: rebuild the dev manifest when route files disappear during an incremental update ([#&#8203;16643](sveltejs/kit#16643))

- breaking: populate env vars before `instrumentation.server.js` is evaluated and update the adapter instrumentation API ([#&#8203;16303](sveltejs/kit#16303))

- fix: only print prerender progress newline when necessary ([#&#8203;16766](sveltejs/kit#16766))

- perf: match only unpaired surrogates when escaping HTML ([#&#8203;16407](sveltejs/kit#16407))

- fix: treat `data:` protocol URLs as external for redirect ([#&#8203;16392](sveltejs/kit#16392))

- chore: deduplicate request hashing for serialized fetch responses ([#&#8203;16499](sveltejs/kit#16499))

- fix: don't treat `Object.prototype` members as param matchers during validation ([#&#8203;16612](sveltejs/kit#16612))

- fix: generate a `never` `Path` type when there are no routes ([#&#8203;17228](sveltejs/kit#17228))

- fix: follow HTTP redirects from authentication proxies when enhancing form submissions ([#&#8203;17106](sveltejs/kit#17106))

- fix: don't report empty environment variables as missing ([#&#8203;16401](sveltejs/kit#16401))

- chore: generate the env modules in a single pass ([#&#8203;16833](sveltejs/kit#16833))

- fix: externalize `@opentelemetry/api` to prevent bundler chunk colocation between `instrumentation.server.js` and application code ([#&#8203;16302](sveltejs/kit#16302))

- fix: support form fields named after Object prototype properties ([#&#8203;17136](sveltejs/kit#17136))

- fix: exclude routes without a page or endpoint from `routes` in `$app/manifest`, and remove directories with no route files from `LayoutParams` ([#&#8203;16588](sveltejs/kit#16588))

- fix: record a history traversal before resolving its route ([#&#8203;16959](sveltejs/kit#16959))

- fix: avoid Vite dev server reload on initial page request ([#&#8203;16553](sveltejs/kit#16553))

- fix: don't set a `null` `accept-language` header on internal `fetch` sub-requests when the incoming request has none ([#&#8203;16527](sveltejs/kit#16527))

- fix: reuse SSR-cached fetch responses during hydration when a cross-origin URL is not in canonical form ([#&#8203;16339](sveltejs/kit#16339))

- fix: correctly detect prerendered paths in server `fetch` when `paths.base` is set ([#&#8203;16525](sveltejs/kit#16525))

- chore: say what a valid remote form field name looks like when rejecting one ([#&#8203;16938](sveltejs/kit#16938))

- chore: warn when remote form fields are enumerated in dev ([#&#8203;16940](sveltejs/kit#16940))

- fix: populate `$app/env/*` dynamic variables in contexts that don't run the dev server, such as `vite-node` ([#&#8203;16223](sveltejs/kit#16223))

- fix: resolve client manifest imports against the Vite root ([#&#8203;16803](sveltejs/kit#16803))

- fix: properly handle Date objects in form.fields.set ([#&#8203;16168](sveltejs/kit#16168))

- fix: return 404 for form actions and remote functions whose name is an `Object.prototype` member ([#&#8203;16072](sveltejs/kit#16072))

- fix: no longer throw "An impossible situation occurred" when a server-only module is imported by both server and client code ([#&#8203;16257](sveltejs/kit#16257))

- fix: respect Vite default log level ([#&#8203;16767](sveltejs/kit#16767))

- fix: set the focus starting point without a fragment navigation, which leaked a `hashchange` to app listeners ([#&#8203;16992](sveltejs/kit#16992))

- fix: keep a `form.for` instance registered when the derived that holds it disconnects and reconnects ([#&#8203;17230](sveltejs/kit#17230))

- fix: make cookie options optional ([#&#8203;17201](sveltejs/kit#17201))

- fix: don't duplicate remote modules in the generated manifest ([#&#8203;16532](sveltejs/kit#16532))

- fix: evict hashed fetch cache entries after mutations ([#&#8203;17146](sveltejs/kit#17146))

- chore: reuse base64 and text decoding helpers ([#&#8203;16608](sveltejs/kit#16608))

- fix: explain the removal of `$lib` and `$service-worker` when their imports fail to resolve ([#&#8203;16635](sveltejs/kit#16635))

- fix: tweak response logging for remote requests ([#&#8203;16865](sveltejs/kit#16865))

- fix: correctly massage stack traces with async frames ([#&#8203;16633](sveltejs/kit#16633))

- fix: mark `RequestEvent` properties as `readonly` ([#&#8203;16661](sveltejs/kit#16661))

- fix: render the nearest `+error.svelte` at the depth it occupies when an error is thrown during rendering ([#&#8203;16526](sveltejs/kit#16526))

- fix: support coordinate objects from image inputs in remote forms ([#&#8203;16944](sveltejs/kit#16944))

- fix: revert route metadata caching to regenerate missing root-route types during sync ([#&#8203;17281](sveltejs/kit#17281))

- chore: bump `@sveltejs/acorn-typescript` to 1.0.12 ([#&#8203;16745](sveltejs/kit#16745))

- fix: update `match` parameter type ([#&#8203;16636](sveltejs/kit#16636))

- fix: generate sourcemaps for remote modules ([#&#8203;16440](sveltejs/kit#16440))

- fix: keep hash-router links on the current document when resolving paths ([#&#8203;17107](sveltejs/kit#17107))

- fix: avoid empty getElementById() call on hash routing navigation ([#&#8203;16448](sveltejs/kit#16448))

- fix: resolve every module entry point using `kit.moduleExtensions` ([#&#8203;17043](sveltejs/kit#17043))

- fix: serve `.ico` files with `image/x-icon` Content-Type ([#&#8203;16234](sveltejs/kit#16234))

- chore: bump `magic-string` to 1.1.0 ([#&#8203;16745](sveltejs/kit#16745))

- fix: exclude inlined files from the page's `$app/manifest` immutable list ([#&#8203;16531](sveltejs/kit#16531))

- fix: discard invalidation results when a navigation completes while they load ([#&#8203;16852](sveltejs/kit#16852))

- fix: avoid client-side code being bundled by Cloudflare Wrangler ([#&#8203;16364](sveltejs/kit#16364))

- fix: wait for the redirect navigation before remote form submissions resolve ([#&#8203;16765](sveltejs/kit#16765))

- fix: record the mime types of prerendered paths in the server manifest ([#&#8203;16564](sveltejs/kit#16564))

- fix: only require the `svelte-trusted-html` trusted-types policy when client-side code is shipped, allowing builds where all pages have `csr: false` ([#&#8203;16928](sveltejs/kit#16928))

- chore: clarify which hooks run during server route resolution ([#&#8203;16397](sveltejs/kit#16397))

- fix: yield to allow prerender updates to be visible ([#&#8203;16748](sveltejs/kit#16748))

- fix: make `paths.origin` type looser ([#&#8203;16215](sveltejs/kit#16215))

- chore: bump `devalue` to 5.9.0 ([#&#8203;16745](sveltejs/kit#16745))

- feat: send periodic `keep-alive` SSE comments from `query.live` to prevent idle-timeout errors ([#&#8203;16063](sveltejs/kit#16063))

- fix: send an explicit SSE Accept header for `query.live` requests to avoid buffering by proxies ([#&#8203;17104](sveltejs/kit#17104))

- fix: don't touch the `query.live` stream controller after teardown, and make response cancellation observable via the generator's `request.signal` ([#&#8203;16790](sveltejs/kit#16790))

- fix: print `builder.log.warn` messages to stderr, as documented ([#&#8203;17253](sveltejs/kit#17253))

- fix: warn if hook files are spelled as "hook" instead of "hooks" ([#&#8203;16483](sveltejs/kit#16483))

- fix: only suggest a `+` prefix for route filenames that are valid with the file's extension ([#&#8203;16837](sveltejs/kit#16837))

- chore: only generate each route's resolution module once when prerendering ([#&#8203;16576](sveltejs/kit#16576))

- fix: don't throw from remote form `validate()` if the form unmounts while it is waiting for a tick ([#&#8203;16720](sveltejs/kit#16720))

- chore: share navigation completion between navigate and shallow routing ([#&#8203;16838](sveltejs/kit#16838))

- fix: route dev-server response logging through Vite's logger so it respects `logLevel` and `customLogger` ([#&#8203;16858](sveltejs/kit#16858))

- fix: skip clean fields when programmatically validating forms ([#&#8203;16208](sveltejs/kit#16208))

- perf: skip import graph collection outside client environments ([#&#8203;16383](sveltejs/kit#16383))

- breaking: experimental remote form `validate({ includeUntouched })` option is now `all` ([#&#8203;16208](sveltejs/kit#16208))

- fix: rerun load functions when the number of values of a tracked search parameter changes ([#&#8203;16495](sveltejs/kit#16495))

- chore: read build-time config from defines on the server instead of carrying it in `options` ([#&#8203;16873](sveltejs/kit#16873))

- fix: avoid client build warning about externalising `node:async_hooks` ([#&#8203;16244](sveltejs/kit#16244))

- chore: stop externalizing `cookie` dependency during build ([#&#8203;16936](sveltejs/kit#16936))

- fix: reinstate `$app/environment` as an alias for `$app/env`, in case dependencies import it ([#&#8203;15964](sveltejs/kit#15964))

- fix: preserve `paths.base` when `vite preview` redirects a prerendered page to the correct trailing slash ([#&#8203;16836](sveltejs/kit#16836))

- fix: error when reading non-serialized `set-cookie` headers via `getSetCookie` in `load` ([#&#8203;16614](sveltejs/kit#16614))

- fix: walk and copy directories without a stat per file ([#&#8203;16995](sveltejs/kit#16995))

- perf: avoid quadratic remote form issue merging ([#&#8203;16493](sveltejs/kit#16493))

- fix: widen remote form fields for union schemas and string enums ([#&#8203;16937](sveltejs/kit#16937))

- chore: deprecate the `alias` option ([#&#8203;16470](sveltejs/kit#16470))

- fix: don't attempt to serialize fetch responses when the request body is not a string or TypedArray ([#&#8203;16501](sveltejs/kit#16501))

- fix: respond to `HEAD` requests without a body ([#&#8203;17036](sveltejs/kit#17036))

- chore: replace deprecated Vite dev server APIs ([#&#8203;16961](sveltejs/kit#16961))

- chore: iterate the query cache maps through a single generator ([#&#8203;16846](sveltejs/kit#16846))

- fix: handle rejected streamed server data after delayed loads ([#&#8203;16268](sveltejs/kit#16268))

- fix: don't crash on interactions inside a form whose controls shadow `nodeName` ([#&#8203;16769](sveltejs/kit#16769))

- fix: don't replay a preloaded redirect when a later hop of the navigation returns to the route ([#&#8203;16955](sveltejs/kit#16955))

- fix: prevent path traversal when previewing prerendered pages and data on Windows ([#&#8203;17293](sveltejs/kit#17293))

- fix: settle a query's pending request in place when its value arrives through `set()` ([#&#8203;16958](sveltejs/kit#16958))

- fix: render pages over sibling endpoints without GET or HEAD handlers ([#&#8203;16125](sveltejs/kit#16125))

- fix: exit build workers after completing their tasks while allowing synchronous exit handlers to run ([#&#8203;17135](sveltejs/kit#17135))

- fix: prevent infinite loops when server-side queries refresh each other in a cycle during the single-flight drain ([#&#8203;16461](sveltejs/kit#16461))

- fix: populate `version` in service workers ([#&#8203;16434](sveltejs/kit#16434))

- feat: add field.touched() helper to remote form fields ([#&#8203;14692](sveltejs/kit#14692))

- fix: respect `paths.relative` for server-side route resolution imports ([#&#8203;17056](https://github.com/sveltejs/kit/pull/17056))

- fix: read the error status of `App.Error` in the `prerender` and `query.live` remote functions ([#&#8203;16529](https://github.com/sveltejs/kit/pull/16529))

- fix: resolve remote modules as external during dev prebundling so packages can re-export remote functions ([#&#8203;16426](https://github.com/sveltejs/kit/pull/16426))

- chore: standardize remote-function and shared form diagnostics ([#&#8203;17277](https://github.com/sveltejs/kit/pull/17277))

- fix: avoid `Promise.withResolvers` in client remote functions for older browser support ([#&#8203;16777](https://github.com/sveltejs/kit/pull/16777))

- fix: propagate errors from prerendered remote responses instead of re-running the function ([#&#8203;16535](https://github.com/sveltejs/kit/pull/16535))

- chore: remove unused helpers ([#&#8203;16834](https://github.com/sveltejs/kit/pull/16834))

- fix: allow reserved words (e.g. `delete`, `class`) as remote function export names ([#&#8203;16264](https://github.com/sveltejs/kit/pull/16264))

- fix: reset failed `<svelte:boundary>` on client navigation so a stale `+error.svelte` is torn down ([#&#8203;16296](https://github.com/sveltejs/kit/pull/16296))

- fix: clear `navigating` when a shallow popstate aborts an in-flight navigation ([#&#8203;17118](https://github.com/sveltejs/kit/pull/17118))

- fix: expand `[x+nn]` and `[u+nnnn]` escape sequences when resolving a route id to a pathname ([#&#8203;16570](https://github.com/sveltejs/kit/pull/16570))

- fix: respect user-set `server.cors` and `preview.cors` config instead of overriding them ([#&#8203;16924](https://github.com/sveltejs/kit/pull/16924))

- fix: respect the status returned from `handleError` on the fallback error page served to error-page sub-requests ([#&#8203;16528](https://github.com/sveltejs/kit/pull/16528))

- fix: restore scroll position after back-forward cache returns ([#&#8203;17255](https://github.com/sveltejs/kit/pull/17255))

- fix: warn if there are plugins using `transformIndexHtml` ([#&#8203;16394](https://github.com/sveltejs/kit/pull/16394))

- fix: refetch route-tracking server data when navigating away from an error page ([#&#8203;16381](https://github.com/sveltejs/kit/pull/16381))

- fix: allow routes to contain `[` and `]` via the `[x+5b]` and `[x+5d]` escapes ([#&#8203;16569](https://github.com/sveltejs/kit/pull/16569))

- chore: use `Response.json` instead of the deprecated `json` helper in runtime responses ([#&#8203;16804](https://github.com/sveltejs/kit/pull/16804))

- fix: recommend safe include and exclude patterns in tsconfig warning ([#&#8203;17102](https://github.com/sveltejs/kit/pull/17102))

- chore: remove dependency on kleur ([#&#8203;12548](sveltejs/kit#12548))

- fix: prevent server-side self-fetch fallbacks from following redirects ([#&#8203;17293](sveltejs/kit#17293))

- fix: serialize `query(...).set(...)`/`query(...).refresh()` values into the rendered HTML when called from within a query during SSR ([#&#8203;16461](sveltejs/kit#16461))

- chore: configure the server runtime in one place, deprecate `Server` in favour of the `server` object written by `builder.generateServerInstance` ([#&#8203;17000](https://github.com/sveltejs/kit/pull/17000))

- chore: derive `content-length` from fixed response bodies in `setResponse` ([#&#8203;16794](https://github.com/sveltejs/kit/pull/16794))

- fix: correctly read zero-length files at the end of a binary form payload ([#&#8203;16783](sveltejs/kit#16783))

- fix: reject fallback handlers on prerendered endpoints ([#&#8203;17140](https://github.com/sveltejs/kit/pull/17140))

- fix: don't destroy partial-line app output with the prerender progress line ([#&#8203;16750](https://github.com/sveltejs/kit/pull/16750))

- chore: remove virtual modules ([#&#8203;16813](https://github.com/sveltejs/kit/pull/16813))

- fix: surface prerender errors during development ([#&#8203;16507](https://github.com/sveltejs/kit/pull/16507))

- chore: bump `cookie` to 2.0.1 ([#&#8203;16745](sveltejs/kit#16745))

- fix: detect `$app/server` and `$app/env/private` client imports when SvelteKit is installed inside the project root ([#&#8203;16648](https://github.com/sveltejs/kit/pull/16648))

- chore: read `options` from a single module instead of passing it through the server runtime ([#&#8203;16871](https://github.com/sveltejs/kit/pull/16871))

- fix: wait for the redirect navigation before prerendered remote functions resolve ([#&#8203;16765](sveltejs/kit#16765))

- fix: sort directory entries when building the route manifest so node indices are deterministic across runtimes (e.g. Bun and Node) ([#&#8203;16074](https://github.com/sveltejs/kit/pull/16074))

- fix: skip unnecessary `version.json` checks if `updated.current` is already `true` ([#&#8203;16518](https://github.com/sveltejs/kit/pull/16518))

- fix: allow generation of $app/tsconfig without TypeScript installed ([#&#8203;16534](https://github.com/sveltejs/kit/pull/16534))

- chore: remove dependency on `set-cookie-parser` ([#&#8203;15384](https://github.com/sveltejs/kit/pull/15384))

- chore: share the nearest error page walk between client and server ([#&#8203;16774](https://github.com/sveltejs/kit/pull/16774))

- fix: fall back to the page's form actions when a sibling endpoint has no POST handler ([#&#8203;16349](https://github.com/sveltejs/kit/pull/16349))

- fix: record client output extensions in `builder.mimeTypes` ([#&#8203;16908](https://github.com/sveltejs/kit/pull/16908))

- perf: use a `Set` to check element ids when validating fragment links during prerendering ([#&#8203;16494](https://github.com/sveltejs/kit/pull/16494))

- fix: preserve shared client chunk hashes when the app version changes ([#&#8203;16324](https://github.com/sveltejs/kit/pull/16324))

- fix: include hoisted packages in Vite's `server.fs.allow` list ([#&#8203;15998](https://github.com/sveltejs/kit/pull/15998))

- chore: standardize app template diagnostics ([#&#8203;17250](https://github.com/sveltejs/kit/pull/17250))

- chore: standardize Vite plugin, build, prerender and adapter diagnostics ([#&#8203;17253](sveltejs/kit#17253))

- chore: standardize client navigation, preload, snapshot and enhancement diagnostics ([#&#8203;17276](https://github.com/sveltejs/kit/pull/17276))

- chore: standardize configuration, environment and tsconfig diagnostics ([#&#8203;17251](https://github.com/sveltejs/kit/pull/17251))

- chore: standardize public API, `$app/*` and deprecated module diagnostics ([#&#8203;17265](https://github.com/sveltejs/kit/pull/17265))

- chore: standardize route discovery, parameter and route export diagnostics ([#&#8203;17252](https://github.com/sveltejs/kit/pull/17252))

- chore: standardize server request, hook and page diagnostics ([#&#8203;17275](https://github.com/sveltejs/kit/pull/17275))

- fix: preserve metadata on streamed page responses ([#&#8203;16935](https://github.com/sveltejs/kit/pull/16935))

- fix: only include `_app/immutable` files in `$app/manifest`'s `immutable` in the service worker ([#&#8203;16531](sveltejs/kit#16531))

- chore: remove the dead `SSRState.fallback` field and name the server state fork semantics ([#&#8203;16598](https://github.com/sveltejs/kit/pull/16598))

- fix: atomically replace route metadata during sync ([#&#8203;17096](https://github.com/sveltejs/kit/pull/17096))

- fix: import resolved peer dependencies as file URLs so project-relative resolution works on Windows ([#&#8203;16618](https://github.com/sveltejs/kit/pull/16618))

- fix: preserve sourcemap source paths when adapters copy build output ([#&#8203;17082](https://github.com/sveltejs/kit/pull/17082))

- fix: log errors caught by the Vite dev server handler ([#&#8203;16550](https://github.com/sveltejs/kit/pull/16550))

- chore: bump `acorn` to 8.18.0 ([#&#8203;16745](sveltejs/kit#16745))

- fix: resolve `root` per instance of the SvelteKit Vite plugin ([#&#8203;16513](https://github.com/sveltejs/kit/pull/16513))

- fix: report tsconfig parse errors on Windows ([#&#8203;17251](https://github.com/sveltejs/kit/pull/17251))

- fix: return root layout server data for error-page data requests to non-existent routes ([#&#8203;16376](https://github.com/sveltejs/kit/pull/16376))

- fix: prevent prerender crawler from hanging on unterminated unquoted attributes ([#&#8203;17141](https://github.com/sveltejs/kit/pull/17141))

- fix: prevent `await_reactivity_loss` warning and `state_unsafe_mutation` error when the new version detector runs after an `await` ([#&#8203;16915](https://github.com/sveltejs/kit/pull/16915))

- fix: redact nested and typed underscore-prefixed remote form fields after invalid submissions ([#&#8203;17128](https://github.com/sveltejs/kit/pull/17128))

- fix: ignore path casing differences when warning about overridden Vite config on Windows ([#&#8203;16545](https://github.com/sveltejs/kit/pull/16545))

- fix: return a lightweight 404 instead of rendering the error page for subresource requests ([#&#8203;16463](https://github.com/sveltejs/kit/pull/16463))

- fix: preserve stripped path prefixes by making trailing-slash redirects relative ([#&#8203;16431](https://github.com/sveltejs/kit/pull/16431))

- fix: preserve the current URL search parameters when submitting a remote form without JavaScript ([#&#8203;16373](https://github.com/sveltejs/kit/pull/16373))

- fix: only treat files in node\_modules as remote modules when the package has a peer dependency on [@&#8203;sveltejs/kit](https://github.com/sveltejs/kit) ([#&#8203;16492](https://github.com/sveltejs/kit/pull/16492))

- fix: treeshake prerendered remote functions in the right chunks ([#&#8203;16533](https://github.com/sveltejs/kit/pull/16533))

- fix: correctly serialize Node.js buffers returned from remote functions during SSR ([#&#8203;17158](https://github.com/sveltejs/kit/pull/17158))

- fix: preserve errors with read-only stack properties ([#&#8203;17180](https://github.com/sveltejs/kit/pull/17180))

- chore: deduplicate type-stripping logic in `tweak_types` ([#&#8203;16454](https://github.com/sveltejs/kit/pull/16454))

- fix: avoid infinite loop when building with `--watch` flag ([#&#8203;16632](https://github.com/sveltejs/kit/pull/16632))

- chore: unify the `walk` and `list_files` filesystem helpers ([#&#8203;16784](https://github.com/sveltejs/kit/pull/16784))

- fix: error during development if the adapter does not support instrumentation and it exists ([#&#8203;16548](https://github.com/sveltejs/kit/pull/16548))

- fix: use mouseover+mousemove for preloading to reduce events ([#&#8203;16325](https://github.com/sveltejs/kit/pull/16325))

- fix: reject invalid binary form file metadata ([#&#8203;17149](https://github.com/sveltejs/kit/pull/17149))

- fix: error on server-only imports reachable from hooks or service worker files outside the project root ([#&#8203;16912](https://github.com/sveltejs/kit/pull/16912))

- fix: write generated tsconfig to `node_modules/$app/tsconfig.json` so that tools with simplified tsconfig resolution can find it ([#&#8203;16589](https://github.com/sveltejs/kit/pull/16589))

- chore: emit env modules to disk ([#&#8203;16807](https://github.com/sveltejs/kit/pull/16807))

- fix: more informative error message when running a command inside a query or prerender function ([#&#8203;17293](sveltejs/kit#17293))

- fix: adjust error overload for optional `App.Error` parameters ([#&#8203;16725](https://github.com/sveltejs/kit/pull/16725))

- fix: prerender and crawl pages whose `content-type` header carries a `charset` parameter ([#&#8203;16567](https://github.com/sveltejs/kit/pull/16567))

- fix: stream promised `read` results lazily instead of eagerly buffering them ([#&#8203;16622](https://github.com/sveltejs/kit/pull/16622))

- fix: copy worker files emitted by the server build to the client output directory ([#&#8203;16929](https://github.com/sveltejs/kit/pull/16929))

- chore: parse page options and remote modules with Vite's `parseSync` instead of `acorn` ([#&#8203;16947](https://github.com/sveltejs/kit/pull/16947))

- fix: correctly decode `[u+nnnn]` escape sequences above `ffff` ([#&#8203;16611](sveltejs/kit#16611))

- fix: Reject all pending query promises when a query fails before resolving with a value for the first time ([#&#8203;16890](https://github.com/sveltejs/kit/pull/16890))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMzIuNSIsInVwZGF0ZWRJblZlciI6IjQ0LjEzMi41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: Davide Zarantonello <davide@zarantonello.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

improve the typing of static assets import

4 participants