Upgrading to v1.4
v1.4 adopts SvelteKit 3, Svelte 5, Node adapter 6, and pnpm 12. Back up your SQLite database and review local customizations before updating. The release does not require a schema migration.
Runtime and packages
Use Node 22.17 or newer (Node 24 is used in CI and Docker), and the pnpm version pinned in package.json. TypeScript stays on 6 because the current Svelte tooling does not support 7. The lockfile
records both application dependencies and pnpm’s integrity metadata; commit both YAML documents.
pnpm install --frozen-lockfile
pnpm check
pnpm lint
pnpm format:check
pnpm test
pnpm test:e2e Configuration and imports
SvelteKit options now live in sveltekit(...) in vite.config.ts. Remove
the old svelte.config.js. The #lib imports are declared in package.json; include extensions and use index.js for directory exports.
import { Button } from "#lib/components/ui/button/index.js";
import { db } from "#lib/server/db/index.js";
import { dev } from "$app/env";
import { GOOGLE_CLIENT_ID } from "$app/env/private"; The TypeScript config extends $app/tsconfig. Optional OAuth variables are declared in src/env.ts; an empty value disables its provider.
Production origin
Set ORIGIN before building. The Vite configuration passes it to paths.origin, which replaces adapter-node’s runtime origin setting. Rebuild if the
public URL changes. Keep ORIGIN in the runtime environment too because OAuth uses it for
callback URLs.
ORIGIN=https://admin.example.com pnpm build
node --env-file=.env build/index.js
# Docker: bake the public origin into the build
docker build --build-arg ORIGIN=https://admin.example.com -t svelteforge-admin . Permissions and integration changes
- Only the first registered account receives admin access; later accounts are viewers.
- Role changes require admin access. Editors can create/edit content and delete their own content. Viewers cannot mutate content.
- Pass
event.cookiesto session-cookie helpers, and await async session functions. - External OAuth redirects explicitly opt in to the provider’s origin. Use
Response.json()for JSON endpoints.
Verify deployment
The GitHub deployment workflow installs matching server dependencies and verifies the build commit
through /api/health. Confirm login, protected routes, docs, and charts after
deployment. Never run the demo seed against a production database containing customer data.
For customized applications, also consult the official SvelteKit 3 migration guide.