fix(deps): update dependency svelte to v5 [security] - #174
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
February 26, 2026 06:09
e7d174d to
35211e8
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
March 2, 2026 10:09
904f288 to
a4878d6
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
March 9, 2026 04:48
10807d6 to
9f9241b
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
from
March 13, 2026 13:44
9f9241b to
71bba50
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
from
March 21, 2026 17:20
71bba50 to
3d1ad7e
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
2 times, most recently
from
March 30, 2026 17:39
3d1ad7e to
53454f9
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
6 times, most recently
from
April 16, 2026 21:50
93efcf7 to
9e0e67a
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
April 23, 2026 20:49
9239118 to
c266dd4
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
April 30, 2026 21:30
f48c900 to
2aff83e
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
6 times, most recently
from
May 19, 2026 01:10
0c5fd3c to
3471a31
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
4 times, most recently
from
May 29, 2026 00:42
af7cdfa to
c3925d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
2 times, most recently
from
June 2, 2026 01:07
f3f4af6 to
249251c
Compare
renovate
Bot
force-pushed
the
renovate/npm-svelte-vulnerability
branch
3 times, most recently
from
June 18, 2026 21:13
e0c29d1 to
1785623
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.2.8→^5.0.0^4.2.8→^5.0.04.2.20→5.55.7Svelte affected by cross-site scripting via spread attributes in Svelte SSR
CVE-2026-27121 / GHSA-f7gr-6p89-r883
More information
Details
Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering. When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR does not validate dynamic element tag names in
<svelte:element>CVE-2026-27122 / GHSA-m56q-vw4c-c2cp
More information
Details
When using
<svelte:element this={tag}>in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR attribute spreading includes inherited properties from prototype chain
CVE-2026-27125 / GHSA-crpf-4hrx-3jrp
More information
Details
In server-side rendering, attribute spreading on elements (e.g.
<div {...attrs}>) enumerates inherited properties from the object's prototype chain rather than only own properties. In environments whereObject.prototypehas already been polluted — a precondition outside of Svelte's control — this can cause unexpected attributes to appear in SSR output or cause SSR to throw errors. Client-side rendering is not affected.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte vulnerable to XSS during SSR with contenteditable
bind:innerTextandbind:textContentCVE-2026-27901 / GHSA-phwv-c562-gvmh
More information
Details
The contents of
bind:innerTextandbind:textContentoncontenteditableelements were not properly escaped. This could enable HTML injection and Cross-site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte SSR vulnerable to cross-site scripting via spread attributes
CVE-2026-42599 / GHSA-pr6f-5x2q-rwfp
More information
Details
When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires.
This is similar to but different from CVE-2026-27121.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
CVE-2026-42573 / GHSA-rcqx-6q8c-2c42
More information
Details
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.
You are vulnerable if all of the following is true:
nameattribute on an input or button element within that formSeverity
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
sveltejs/svelte (svelte)
v5.57.1Compare Source
Patch Changes
fix: cancel deferred event listeners during cleanup (#18749)
fix: preserve global CSS in components without scopable elements (#18793)
fix: reduce SSR render result garbage collection (#18798)
fix: resolve the fallback of an each block in the enclosing scope (#18803)
perf: speed up parser interactions with Acorn or avoid them where possible (#18740)
fix: prevent effect tree of batches from interfering with each other (#18508)
fix: serialize input default values during server rendering (#18733)
fix: remove
WAS_MARKEDflag in favor ofSet(#18127)fix: throw
set_context_after_initwhensetContextis called after anawaitduring SSR (#18739)fix: make Object.hasOwn reactive for state proxy ownership changes (#18838)
fix: keep
$state.eagerwhen used as a variable initializer (#18809)perf: avoid regex matching in parser where possible (#18736)
fix: in non-async mode, only push variable to current_sources when active_reaction is updating (#18550)
fix: recognise
aria-braillelabelandaria-brailleroledescriptionas known ARIA attributes (#18765)v5.57.0Compare Source
Minor Changes
feat: export
RenderOutput,SyncRenderOutput,CspandSha256Sourcefromsvelte/server(#18648)feat: add
hasfunction tocreateContext(#18472)feat: support
defaultValueon<select>(#18591)feat: add getOrInsert/getOrInsertComputed to SvelteMap (#18728)
Patch Changes
fix: block template store subscriptions on the promise that assigns the store (#18582)
fix: route $derived teardown errors through invoke_error_boundary (#18486)
fix: track SvelteDate snapshots in reactions (#18700)
fix: remove
<svelte:head>anchors on unmount (#18697)fix: warn on undeclared shorthand event handlers on
<svelte:window>,<svelte:document>and<svelte:body>(#18480)perf: reuse the cached value in the
<option>/<select>value guard (#18713)fix: prevent malformed AST output for
<select>with staticvalueattribute (#18449)fix: apply ownership mutation ignores to binding assignments (#18718)
fix: prevent onoutroend from firing twice when compilerOptions.hmr is true (#18655)
fix: preserve whitespace after inline elements when printing (#18685)
perf: fold SSR block-open markers into the branch's first push (#18712)
fix: run
onDestroycallbacks when a server render throws (#18585)fix: report
derived_invalid_exportforexport let x = $derived(...)in runes mode (#18692)fix: never apply class hash to elements inside
<svelte:head>(#18160)fix: keep
defaultCheckedon hydrated radio inputs with spread attributes (#18701)fix: accept
onfocusin/onfocusoutina11y_mouse_events_have_key_events(#18689)perf: O(n²)→O(n) Map lookups for legacy
$:reactive statement ordering (#18602)fix: distinct memoizer on style/class directives (#18466)
fix: measure nested transitions before applying their starting styles (#18647)
fix: don't turn component instances stored in
$stateinto state proxies (#18646)perf: emit
$.only_childfor elements with a single child (#18717)fix: omit
bind:focusedfrom SSR output (it has no HTML attribute) (#18724)fix: more robust rendering of Svelte custom element slots (#18710)
perf: optimize simple object destructuring in
@consttags (#18390)fix: properly apply static textarea value attribute during CSR (#18727)
fix: end a restored reaction context at the end of its synchronous segment (#18694)
fix: keep the dependencies of a reaction that throws, so deriveds it read are neither leaked nor stuck in their error (#18703)
fix: don't resurrect outroing elements when an ancestor block is paused and resumed (#18431)
perf: use
$.comment()for single-comment templates (#18714)chore: move
@types/trusted-typesto devDependencies (#18730)perf: store setters cache as
Setinstead ofArray(#18251)fix: transform derived assignments and select function bindings correctly during server-side rendering (#18669)
fix: keep boolean attributes with an empty string value when rendering attribute objects on the server (#18721)
fix: sync
SvelteURLport signal when the protocol setter clears the port (#18705)fix: block declaration tags and
{@const}on async values read inside closures (#18533)fix: avoid css tree-shaking for exported Snippet (#18540)
perf: treat
<img loading>as a static element again (#18711)fix: prevent
selectedcontentmutation from changing the selected option (#18495)fix: avoid
NaNkeyframe values inslidetransition for elements without a layout box (#18430)fix: preserve line feed character references in attribute values (#18691)
fix: decode uppercase-
Xhex numeric character references (&#X...;) (#18708)chore: clarify when
$effect.preruns relative to DOM updates (#18534)fix: scope SSR boundary failed snippets to their boundary (#18593)
v5.56.10Compare Source
Patch Changes
fix: preserve CSS escape sequences when printing selectors (#18667)
fix: parse
:nth-child(2n of.foo)whereofis not followed by whitespace (#18611)fix: transform expressions inside labeled statements during server compilation (#18617)
docs: clarify that context lookup includes the current component and all ancestors (#18581)
fix: apply CSS custom properties with falsy values on components (#18634)
fix: correctly print
{#await ... catch x}et al (#18645)fix: ignore comments of Program node during migration script (#18656)
fix: reliably resolve append_style to its correct root (#18614)
fix: clean up removed capture event handlers from spread attributes (#18618)
fix: don't corrupt renderer type during SSR's legacy
bind:retry loop (#18616)fix: treat concise arrow function bodies as implicit returns when calculating blockers (#18613)
fix: give effect teardowns the value from before the first write in a flush (#18620)
fix: avoid double-calling a derived reference when destructuring
$derivedof another$derivedduring server-side rendering (#18668)fix: preserve namespaces in CSS type selectors (#18678)
fix: increment private state fields through a non-
thisreceiver (#18622)chore: deduplicate client and server context helpers (#18580)
fix: release
last_propagated_eventafter event propagation settles so it no longer retains the last event's target subtree (#18569)fix: allow custom elements to receive async values as props (#18661)
fix: strip comments from inline
stylevalues in linear time (#18553)fix: prevent declaration comments from breaking server derived references (#18641)
perf: make async blocker analysis scale linearly with the number of top-level references (#18549)
fix: preserve short-circuiting for logical assignments to private state fields (#18594)
v5.56.9Compare Source
Patch Changes
fix: skip controlled each fast path while another batch is pending (#18625)
fix: better whitespace handling inside printer (#18638)
fix: don't duplicate comments in attributes (#18636)
fix: preserve CSS comments in the AST printer (#18637)
v5.56.8Compare Source
Patch Changes
fix: call
onerrorand provide a workingresetwhen hydrating a failed boundary (#18556)fix: preserve select selection when spread attributes omit value (#18561)
v5.56.7Compare Source
Patch Changes
indentoption forprint(#18474)v5.56.6Compare Source
Patch Changes
perf: skip unnecessary blocker analysis when compiling components without top-level await (#18548)
fix: rerun derived that had an abort controller on reconnection (#18551)
v5.56.5Compare Source
Patch Changes
chore: drop dead code that make TSGO fail (#18496)
fix: don't (re)connect deriveds when read inside branch/root effects (#18527)
fix: skip unnecessary derived effect in earlier batch (#18525)
fix: avoid declaration tag warning in event handlers (#18500)
fix: abort deriveds own AbortSignal when it disconnects (#18400)
fix: ensure
$state.eager()is correctly transormed for SSR output (#18530)fix: correctly transform declaration tags during SSR (#18492)
fix: transform computed keys in keyed
{#each}destructuring patterns (#18521)fix: chain preprocessor sourcemaps with an empty
sources[0]instead of dropping them (#18518)fix: clear previous_task reference after abort in Tween to prevent memory leak on interrupted tweens (#18541)
fix: don't treat declaration tags as parts inside each blocks (#18507)
v5.56.4Compare Source
Patch Changes
fix: include wrapping parentheses in
{@const}declaratorendposition (#18436)fix: always unset reactivity context after restoring it (#18453)
fix: don't notify
searchParamssubscribers when the URL changes without affecting the search string (#18425)fix: strip
?from optional parameters in<script lang="ts">so generated JavaScript is valid (#18448)v5.56.3Compare Source
Patch Changes
fix: ignore errors that occur in destroyed effects (#18384)
fix: type BigInts in
$state.snapshot(...)return values (#18388)v5.56.2Compare Source
Patch Changes
fix: properly track effect end node for async sibling component (#18371)
fix: prevent false-positive reactivity loss warning (#18373)
chore: bump esrap dependency (#18372)
fix: ignore declaration tags for animation directive (#18366)
fix: reject pending async deriveds on discard (#18308)
v5.56.1Compare Source
Patch Changes
fix: error at compile time on duplicate snippet/declaration tag definitions (#18351)
fix: parse declaration tag contents more robustly (#18353)
fix: correctly transform references to earlier declarators in a declaration tag (e.g.
{let a = $state(0), b = $derived(a * 2)}) (#18348)fix: avoid spurious
state_referenced_locallywarnings for$deriveddeclarations in declaration tags (#18348)fix: tolerate whitespace before
let/constin declaration tags (#18348)fix: prevent infinite loop when a tag's expression ends with a trailing
/at the end of the input (#18350)fix: more robust parsing of declaration tags with regards to
type(#18330)fix: preserve newlines in spread input values when the
typeattribute is applied aftervalue(#18345)fix: update
SvelteURLSearchParamswhen setting duplicate keys to the same joined value (#18336)fix: check references for blockers on server, too (#18352)
v5.56.0Compare Source
Minor Changes
Patch Changes
perf: use
createElementinstead ofcreateElementNSfor HTML elements (#18262)perf: store
current_sourcesas aSetfor O(1) membership checks (#18278)perf: deduplicate identical hoisted templates within a component (#18320)
perf: hoist
rest_propsexclude list as a module-scopeSet(#18252)v5.55.10Compare Source
Patch Changes
fix: unlink errored and otherwise finished batch (#18264)
perf: walk composedPath() directly in delegated event propagation (#18268)
fix: transfer effects when merging batches (#18254)
fix: allow
$derived(await ...)in disconnected effect roots (#18273)fix: remove temporary raw-text hydration markers (#18269)
fix: propagate async
@constblockers through closure references so template expressions like{(() => host)()}correctly wait for the awaited value (#18309)fix: properly unlink batches (#18298)
fix: settle discarded batch (#18290)
fix: declare
let:directives before{@const}declarations on slotted elements (#18271)fix: resume outro-ed branches if they were kept around (#18291)
fix: avoid waterfall-warning when async resolves to same value (#18297)
fix: correctly coordinate component-level effects inside async blocks (#18260)
fix: make unnecessary commit work less likely (#18263)
chore: add tag name to
a11y_click_events_have_key_eventswarning (#18272)fix: catch rejected promises while merging/committing (#18266)
v5.55.9Compare Source
Patch Changes
fix: don't unset batch when calling
{#await ...}promise (#18243)fix: promise-ify
{#await await ...}expressions on the server and correctly hydrate them on the client (#18243)fix: deduplicate dependencies that are added outside the init/update cycle (#18243)
fix: avoid false-positive batch invariant error (#18246)
fix: inline primitive constants in attribute values during SSR (#18232)
v5.55.8Compare Source
Patch Changes
fix(print): handle
svelte:bodyand fix keyframe percentage double-printing (#18234)fix: execute uninitialized derived even if it's destroyed (#18228)
fix: use named symbols everywhere (#18238)
fix: don't run teardown effects when deriveds are unfreezed (#18227)
fix: unset context synchronously in
run(#18236)v5.55.7Compare Source
Patch Changes
fix: prevent XSS on
hydratablefrom user contents (a16ebc67bbcf8f708360195687e1b2719463e1a4)chore: bump devalue (#18219)
fix: disallow empty attribute names during SSR (
547853e2406a2147ad7fb5ffeba95b01bd9642da)fix: harden regex (
d2375e2ebcab5c88feb5652f1a9d621b8f06b259)fix: move Svelte runtime properties to symbols (
e1cbbd96441e82c9eb8a23a2903c0d06d3cda991)v5.55.6Compare Source
Patch Changes
fix: leave stale promises to wait for a later resolution, instead of rejecting (#18180)
fix: keep dependencies of
$state.eager/pending(#18218)fix: reapply context after transforming error during SSR (#18099)
fix: don't rebase just-created batches (#18117)
chore: allow
nullforpendingin typings (#18201)fix: flush eager effects in production (#18107)
fix: rethrow error of failed iterable after calling
return()(#18169)fix: account for proxified instance when updating
bind:this(#18147)fix: ensure scheduled batch is flushed if not obsolete (#18131)
fix: resolve stale deriveds with latest value (#18167)
chore: remove unnecessary
increment_pendingcalls (#18183)fix: correctly compile component member expressions for SSR (#18192)
fix: reset
source.updatedstack traces afterflush(#18196)fix: replacing async 'blocking' strategy with 'merging' (#18205)
fix: allow
@debugtags to reference awaited variables (#18138)fix: re-run fallback props if dependencies update (#18146)
fix: abort running obsolete async branches (#18118)
fix: ignore comments when reading CSS values (#18153)
fix: wrap
Promise.allinsaveduring SSR (#18178)fix: ignore false-positive errors of
$inspectdependencies (#18106)v5.55.5Compare Source
Patch Changes
fix: don't mark deriveds while an effect is updating (#18124)
fix: do not dispatch introstart event with animation of animate directive (#18122)
v5.55.4Compare Source
Patch Changes
fix: never mark a child effect root as inert (#18111)
fix: reset context after waiting on blockers of
@constexpressions (#18100)fix: keep flushing new eager effects (#18102)
v5.55.3Compare Source
Patch Changes
fix: ensure proper HMR updates for dynamic components (#18079)
fix: correctly calculate
@constblockers (#18039)fix: freeze deriveds once their containing effects are destroyed (#17921)
fix: defer error boundary rendering in forks (#18076)
fix: avoid false positives for reactivity loss warning (#18088)
v5.55.2Compare Source
Patch Changes
fix: invalidate
@consttags based on visible references in legacy mode (#18041)fix: handle parens in template expressions more robustly (#18075)
fix: disallow
--inidPrefix(#18038)fix: correct types for
ontoggleon<details>elements (#18063)fix: don't override
$destroy/set/oninstance methods in dev mode (#18034)fix: unskip branches of earlier batches after commit (#18048)
fix: never set derived.v inside fork (#18037)
fix: skip rebase logic in non-async mode (#18040)
fix: don't reset status of uninitialized deriveds (#18054)
v5.55.1Compare Source
Patch Changes
fix: correctly handle bindings on the server (#18009)
fix: prevent hydration error on async
{@html ...}(#17999)fix: cleanup
superTypeParametersinClassDeclarations/ClassExpression(#18015)fix: improve duplicate module import error message (#18016)
fix: reschedule new effects in prior batches (#18021)
v5.55.0Compare Source
Minor Changes
Patch Changes
v5.54.1Compare Source
Patch Changes
fix: hydration comments during hmr (#17975)
fix: null out
effect.bindestroy_effect(#17980)fix: group sync statements (#17977)
fix: defer batch resolution until earlier intersecting batches have committed (#17162)
fix: properly invoke
iterator.return()during reactivity loss check (#17966)fix: remove trailing semicolon from {@const} tag printer (#17962)
v5.54.0Compare Source
Minor Changes
css,runes,customElementcompiler options to be functions (#17951)Patch Changes
v5.53.13Compare Source
Patch Changes
fix: ensure
$inspectafter top level await doesn't break builds (#17943)fix: resume inert effects when they come from offscreen (#17942)
fix: don't eagerly access not-yet-initialized functions in template (#17938)
fix: discard batches made obsolete by commit (#17934)
fix: ensure "is standalone child" is correctly reset (#17944)
fix: remove nodes in boundary when work is pending and HMR is active (#17932)
v5.53.12Compare Source
Patch Changes
fix: update
select.__valueonchange(#17745)chore: add
invarianthelper for debugging (#17929)fix: ensure deriveds values are correct across batches (#17917)
fix: handle async RHS in
assignment_value_stale(#17925)fix: avoid traversing clean roots (#17928)
v5.53.11Compare Source
Patch Changes
fix: remove
untrackcircular dependency (#17910)fix: recover from errors that leave a corrupted effect tree (#17888)
fix: properly lazily evaluate RHS when checking for
assignment_value_stale(#17906)fix: resolve boundary in correct batch when hydrating (#17914)
chore: rebase batches after process, not during (#17900)
v5.53.10Compare Source
Patch Changes
v5.53.9Compare Source
Patch Changes
bind:thiscleanup timing (#17885)v5.53.8Compare Source
Patch Changes
fix:
{@html}no longer duplicates content insidecontenteditableelements (#17853)fix: don't access inert block effects (#17882)
fix: handle asnyc updates within pending boundary (#17873)
perf: avoid re-traversing the effect tree after
$:assignments (#17848)chore: simplify scheduling logic (#17805)
v5.53.7Compare Source
Patch Changes
fix: correctly add __svelte_meta after else-if chains (#17830)
perf: cache element interactivity and source line splitting in compiler (#17839)
chore: avoid rescheduling effects during branch commit (#17837)
perf: optimize CSS selector pruning (#17846)
fix: preserve original boundary errors when keyed each rows are removed during async updates (#17843)
perf: avoid O(n²) name scanning in scope
generateandunique(#17844)fix: preserve each items that are needed by pending batches (#17819)
v5.53.6Compare Source
Patch Changes
perf: optimize parser hot paths for faster compilation (#17811)
fix:
SvelteMapincorrectly handles keys withundefinedvalues (#17826)fix: SvelteURL
searchsetter now returns the normalized value, matching native URL behavior (#17828)fix: visit synthetic value node during ssr (#17824)
fix: always case insensitive event handlers during ssr (#17822)
chore: more efficient effect scheduling (#17808)
perf: optimize compiler analysis phase (#17823)
fix: skip redundant batch.apply (#17816)
chore: null out current_batch before committing branches (#17809)
v5.53.5Compare Source
Patch Changes
fix: escape
innerTextandtextContentbindings ofcontenteditable(0df5abcae223058ceb95491470372065fb87951d)fix: sanitize
transformErrorvalues prior to embedding in HTML comments (0298e979371bb583855c9810db79a70a551d22b9)v5.53.4Compare Source
Patch Changes
fix: set server context after async transformError (#17799)
fix: hydrate if blocks correctly (#17784)
fix: handle default parameters scope leaks (#17788)
fix: prevent flushed effects from running again (#17787)
v5.53.3Compare Source
Patch Changes
fix: render
:catchof#awaitblock with correct key (#17769)chore: pin aria-query@5.3.1 (#17772)
fix: make string coercion consistent to
toString(#17774)v5.53.2Compare Source
Patch Changes
fix: update expressions on server deriveds (#17767)
fix: further obfuscate
node:cryptoimport from overzealous static analysis (#17763)v5.53.1[Compare Source](https://redirect.github.com/sveltejs/svelte/compare/s
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.