Conversation
Bumps [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte) from 4.2.18 to 5.53.5. - [Release notes](https://github.com/sveltejs/svelte/releases) - [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.53.5/packages/svelte) --- updated-dependencies: - dependency-name: svelte dependency-version: 5.53.5 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
| "eslint-plugin-svelte": "^2.35.1", | ||
| "prettier": "^3.1.1", | ||
| "prettier-plugin-svelte": "^3.1.2", | ||
| "svelte": "^4.2.7", | ||
| "svelte": "^5.53.5", | ||
| "svelte-check": "^3.6.0", | ||
| "tslib": "^2.4.1", | ||
| "typescript": "^5.0.0", |
There was a problem hiding this comment.
Bug: The svelte package was upgraded to v5, but its dependencies @sveltejs/kit and @sveltejs/vite-plugin-svelte were not, creating incompatible peer dependencies that will cause build failures.
Severity: CRITICAL
Suggested Fix
To resolve the incompatibility, either revert the svelte package upgrade back to a 4.x version, or upgrade both @sveltejs/kit to a version compatible with Svelte 5 (like SvelteKit 3) and @sveltejs/vite-plugin-svelte to version 4.x or higher.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: apps/sveltekit-2/package.json#L25-L31
Potential issue: The `svelte` dependency was upgraded from version 4 to 5, but related
packages `@sveltejs/kit` (at `^2.0.0`) and `@sveltejs/vite-plugin-svelte` (at `^3.0.0`)
were not updated. SvelteKit 2.x is officially compatible with Svelte 4.x, not Svelte 5.
Furthermore, `@sveltejs/vite-plugin-svelte` version 3.x is designed for Svelte 4, while
Svelte 5 requires version 4.x of the plugin. This version mismatch will cause peer
dependency conflicts, which will prevent the application from building or running
correctly.
Did we get this right? 👍 / 👎 to inform future reviews.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
| "prettier": "^3.1.1", | ||
| "prettier-plugin-svelte": "^3.1.2", | ||
| "svelte": "^4.2.7", | ||
| "svelte": "^5.53.5", |
There was a problem hiding this comment.
Major Svelte bump without updating companion tooling packages
High Severity
Bumping svelte from v4 to v5 without updating @sveltejs/vite-plugin-svelte (currently ^3.0.0, needs v5+) and svelte-check (currently ^3.6.0, needs v4+) will likely break the build. Notably, @sveltejs/vite-plugin-svelte@3.1.1 pulls in svelte-hmr@0.16.0, which has a peer dependency of svelte: ^3.19.0 || ^4.0.0 — explicitly excluding Svelte 5. This is a major version migration that requires coordinated upgrades of the entire Svelte tooling ecosystem.


Bumps svelte from 4.2.18 to 5.53.5.
Release notes
Sourced from svelte's releases.
... (truncated)
Changelog
Sourced from svelte's changelog.
... (truncated)
Commits
ed14b49Version Packages (#17802)0df5abcMerge commit from fork0298e97Merge commit from fork96fd3ceVersion Packages (#17786)1b3e660fix: prevent flushed effects from running again (#17787)673a1abfix: set server context after async transformError (#17799)3a28979fix: handle default parameters scope leaks (#17788)fcdc028fix: hydrate if blocks correctly (#17784)97f3ac5Version Packages (#17775)7deedc5fix: render:catchof#awaitblock with correct key (#17769)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for svelte since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.