Dev News Daily ENDE

SvelteKit 3.0 requires Vite 8 and TypeScript 6 and swaps $lib for #lib

SvelteKit 3.0.0 was published on 1 October, together with new major versions of all its official adapters: adapter-node 6, adapter-vercel 7, adapter-netlify 7, adapter-cloudflare 8 and adapter-static 4, plus @sveltejs/package 3 and enhanced-img 1.0. The release notes run to dozens of entries, and most of them are marked breaking.

New floors. SvelteKit 3 requires Vite 8, at least 8.0.12, the first Vite release that bundles the stable Rolldown 1.0, together with @sveltejs/vite-plugin-svelte 7 and TypeScript 6. Svelte configuration options now have to be passed through the Vite plugin.

Changes that touch most apps.

  • The $lib alias is replaced by #lib, the files.lib option is removed, and imports through #lib need explicit file extensions.
  • base, assets and resolveRoute are removed from $app/paths, and a new kit.paths.origin option replaces both kit.prerender.origin and the ORIGIN environment variable of the Node adapter.
  • goto's noScroll and keepFocus options become a single reset option, with data-sveltekit-reset replacing the two matching attributes. goto now rejects a URL that does not resolve to a route in the app.
  • refreshAll arrives and invalidateAll is deprecated. Clicking a link to the current URL now reruns all load functions and queries.
  • error(status, {...}) is deprecated in favour of error(status, message, {...}), all errors now go through the handleError hook, and that hook can influence the status code.

Server and security behaviour. Cross-origin form submissions without a Content-Type header are refused. The deprecated CSRF checkOrigin option is gone in favour of trustedOrigins. Query parameters starting with x-sveltekit- are rejected. Directories named server are treated as server-only anywhere in the project, except under src/routes and the assets directory. Cookie names must now be ASCII, after an upgrade to cookie v2. Form action responses use the HTTP status returned from fail.

Smaller removals. The preloadStrategy option is gone, as modulepreload is always used, with a new linkHeaderPreload option for preloading through the Link header. Version polling now also checks for new deployments on data and form responses and on tab focus, and its default interval is one hour. Tracing leaves the experimental namespace. Remote function files are refused unless experimental.remoteFunctions is on.

SvelteKit 3.0 requires Vite 8 and TypeScript 6 and swaps $lib for #lib
SvelteKit 3.0 requires Vite 8 and TypeScript 6 and swaps $lib for #lib — Dev News Daily

What it means

This is a migration release, not a feature release. Teams should plan the Vite 8 and TypeScript 6 upgrades first, since everything else depends on them, and then work through the $lib, $app/paths and goto changes, which are the ones most code will hit. Apps deployed with the Node adapter that set ORIGIN need the new paths.origin setting, or URLs built on the server may come out wrong.