Upgrading to v1.4

v1.4 adopts SvelteKit 3, Svelte 5, Node adapter 6, and pnpm 12. Back up your SQLite database and review local customizations before updating. The release does not require a schema migration.

Runtime and packages

Use Node 22.17 or newer (Node 24 is used in CI and Docker), and the pnpm version pinned in package.json. TypeScript stays on 6 because the current Svelte tooling does not support 7. The lockfile records both application dependencies and pnpm’s integrity metadata; commit both YAML documents.

pnpm install --frozen-lockfile
pnpm check
pnpm lint
pnpm format:check
pnpm test
pnpm test:e2e

Configuration and imports

SvelteKit options now live in sveltekit(...) in vite.config.ts. Remove the old svelte.config.js. The #lib imports are declared in package.json; include extensions and use index.js for directory exports.

import { Button } from "#lib/components/ui/button/index.js";
import { db } from "#lib/server/db/index.js";
import { dev } from "$app/env";
import { GOOGLE_CLIENT_ID } from "$app/env/private";

The TypeScript config extends $app/tsconfig. Optional OAuth variables are declared in src/env.ts; an empty value disables its provider.

Production origin

Set ORIGIN before building. The Vite configuration passes it to paths.origin, which replaces adapter-node’s runtime origin setting. Rebuild if the public URL changes. Keep ORIGIN in the runtime environment too because OAuth uses it for callback URLs.

ORIGIN=https://admin.example.com pnpm build
node --env-file=.env build/index.js

# Docker: bake the public origin into the build
docker build --build-arg ORIGIN=https://admin.example.com -t svelteforge-admin .

Permissions and integration changes

  • Only the first registered account receives admin access; later accounts are viewers.
  • Role changes require admin access. Editors can create/edit content and delete their own content. Viewers cannot mutate content.
  • Pass event.cookies to session-cookie helpers, and await async session functions.
  • External OAuth redirects explicitly opt in to the provider’s origin. Use Response.json() for JSON endpoints.

Verify deployment

The GitHub deployment workflow installs matching server dependencies and verifies the build commit through /api/health. Confirm login, protected routes, docs, and charts after deployment. Never run the demo seed against a production database containing customer data.

For customized applications, also consult the official SvelteKit 3 migration guide.