Conversation
Run `sv migrate sveltekit-3` and finish the manual steps from the migration guide: - move kit config from svelte.config.js into the sveltekit() vite plugin - replace $lib and the deprecated $lib-docs alias with #lib / #lib-docs subpath imports (package.json "imports"), incl. the icons-meta generator and shadcn-svelte components.json (bump to 1.7 for # alias support) - extend $app/tsconfig, drop stale jsconfig.json - $app/environment -> $app/env, goto replaceState -> replace, resolve() pathnames without leading slash - bump kit 3, adapter-auto 8, package 3, svelte 5.57.1, typescript 6 - drop cookie 0.7.0 override (kit 3 depends on cookie ^2)
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
npm 10 (Node 22 in CI) installs a nested @sveltejs/kit 2 to satisfy runed's optional peer, so the lockfile written by npm 11 fails npm ci. Override the peer to the root kit 3 so both npm versions resolve the same tree.
Allow PostHog's lazy-loaded scripts from eu-assets.i.posthog.com in script-src. Move mode-watcher's anti-flash snippet into app.html with %sveltekit.nonce% (filled by a hooks.server.ts transformPageChunk), since SvelteKit only substitutes the nonce placeholder in app.html and the component-injected script was being blocked.
Add worker-src 'self' blob: data: so the session recorder's compression worker is not blocked by the script-src fallback, and allow https://eu.posthog.com in connect-src for the toolbar.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Migrates the repo to SvelteKit 3 following the release post and the migration guide. Started with
npx sv migrate sveltekit-3 --tasks all, then did the manual steps and fixed what the tool got wrong.Changes
Config
svelte.config.jsremoved. Adapter and CSP moved intosveltekit({...})invite.config.js. CSP directives are unchanged.tsconfig.jsonnow extends$app/tsconfig. Dropped the options the base already sets. Includessrc+ root files.tailwind.config.jsis excluded (see notes).jsconfig.json. It was a stale leftover, and the migration tool updated it instead oftsconfig.json.Aliases -> subpath imports
$lib->#lib, using theimportsfield in package.json.$lib-docs->#lib-docs. Kit 3 deprecatesconfig.alias(config_option_deprecated_alias), so this alias moves to a subpath import too.scripts/indexIcons.tsand its spec now emit#lib/icons/..., sonpm run indexwon't bring back$lib.components.jsonaliases now use#lib-docs. Bumpedshadcn-svelteto 1.7, which resolves#aliases through package.jsonimports.dist/has no#lib/$libspecifiers. The library itself never used aliases.API renames
$app/environment->$app/envgoto(..., { replaceState: true })->{ replace: true }resolve('/icons')->resolve('icons'). Pathnames no longer take a leading/.Deps
cookie: 0.7.0override. It was a CVE patch for kit 2'scookie@^0.6. Kit 3 depends oncookie@^2, so the pin would have forced an incompatible major.overrides.runed.@sveltejs/kit = $@sveltejs/kit. runed (via bits-ui) still declares an optional@sveltejs/kit ^2peer. npm 10 (Node 22, used in CI) installs a nested kit 2 to satisfy it, and npm 11 doesn't, so the lockfile only stayed in sync for one of them. The override makes runed use the root kit 3. Cleannpm cinow works with both npm 10 and 11.node-version: 22resolves to the latest 22.x, and release uses 24. No workflow change needed.CSP fixes (these were already broken on
main; the directives used to be copied unchanged)script-srcnow allowshttps://eu-assets.i.posthog.com. posthog-js lazy-loads config, recorder, surveys, web-vitals and dead-clicks scripts from there, and all of them were blocked.worker-src 'self' blob: data:for the session recorder's compression worker, andhttps://eu.posthog.comtoconnect-srcfor the toolbar.%sveltekit.nonce%insideapp.html, so the snippet now lives there (<script nonce="%sveltekit.nonce%">%modewatcher.snippet%</script>).src/hooks.server.tsfills it in throughtransformPageChunk, using mode-watcher's owngenerateSetInitialModeExpression(), and<ModeWatcher disableHeadScriptInjection />stops the component from injecting its own copy.vite preview: every<script>carries the header nonce, no placeholders leak into the HTML, light and dark mode apply before hydration, and the console shows no CSP violations.Verification
From a clean
npm ci, all CI steps pass:npm run check: 0 errors / 0 warnings, no kit deprecation warningsnpm run lint: passesnpm test: 1120 passednpm run check:icons: 555 conformnpm run package: publint "All good"Two local Codex review passes; the final one returned no issues.
Smoke test with
vite build+vite preview:/,/icons, and/?search=bellall work. The last one redirects to/icons?search=bellwith the filter applied.Notes / follow-ups (not in this PR)
tailwind.config.jsis never loaded: Tailwind v4 has no@configinapp.css. I excluded it from typecheck instead of editing dead code. It can probably be deleted, along withtailwindcss-animateandautoprefixer.tsconfig.jsondoesn't typecheckscripts/. The old config didn't either, and the generator is covered by its vitest spec.npm auditstill lists issues in packages this PR doesn't touch (brace-expansion, undici, nanoid, ...).