fix: server-only import guard misses entrypoints outside the project root - #16912
Merged
elliott-with-the-longest-name-on-github merged 1 commit intoAug 25, 2026
Merged
Conversation
|
Install the latest version of pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/437617288c9dcc77447affdc780c1c74cdd36a79Open in |
🦋 Changeset detectedLatest commit: 4376172 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
elliott-with-the-longest-name-on-github
approved these changes
Aug 25, 2026
elliott-with-the-longest-name-on-github
merged commit Aug 25, 2026
f2c5102
into
version-3
104 of 106 checks passed
elliott-with-the-longest-name-on-github
deleted the
guard-out-of-root-hooks
branch
August 25, 2026 21:27
Rich-Harris
pushed a commit
that referenced
this pull request
Aug 26, 2026
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to version-3, this PR will be updated.⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ `version-3` is currently in **pre mode** so this branch has prereleases rather than normal releases. If you want to exit prereleases, run `changeset pre exit` on `version-3`.⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ # Releases ## @sveltejs/adapter-bun@1.0.0-next.2 ### Major Changes - breaking: require Bun 1.4, which routes `HEAD` to `GET` handlers and settles `stop()` after a force close ([#16880](#16880)) ### Patch Changes - fix: build apps that use server instrumentation ([#16898](#16898)) - Updated dependencies [[`ff8cdd4`](ff8cdd4), [`723572c`](723572c), [`3b8e034`](3b8e034), [`f2c5102`](f2c5102), [`c66a6ed`](c66a6ed), [`428e5ef`](428e5ef)]: - @sveltejs/kit@3.0.0-next.26 ## @sveltejs/adapter-node@6.0.0-next.11 ### Patch Changes - chore: remove polka, attach the handler to the http server directly ([#16907](#16907)) - Updated dependencies [[`ff8cdd4`](ff8cdd4), [`723572c`](723572c), [`3b8e034`](3b8e034), [`f2c5102`](f2c5102), [`c66a6ed`](c66a6ed), [`428e5ef`](428e5ef)]: - @sveltejs/kit@3.0.0-next.26 ## @sveltejs/kit@3.0.0-next.26 ### Patch Changes - fix: only require the `svelte-trusted-html` trusted-types policy when client-side code is shipped, allowing builds where all pages have `csr: false` ([#16928](#16928)) - chore: stop externalizing `cookie` dependency during build ([#16936](#16936)) - fix: preserve metadata on streamed page responses ([#16935](#16935)) - fix: error on server-only imports reachable from hooks or service worker files outside the project root ([#16912](#16912)) - fix: copy worker files emitted by the server build to the client output directory ([#16929](#16929)) - fix: Reject all pending query promises when a query fails before resolving with a value for the first time ([#16890](#16890)) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ran into this in a monorepo where several apps share one client hooks file. When
files.hooks.clientpoints outside the project root,vite-plugin-sveltekit-guardsilently stops detecting server-only imports reachable from it. A$app/env/privateimport in the hooks file builds cleanly instead of throwing, even though out-of-root hooks are supported (their directory is added toserver.fs.allow).The guard's import map keys go through
normalize_id, which leaves ids outside the root absolute, but entrypoints were added as root-relative manifest paths like../shared/hooks.client.js, so the upward walk never matches the hooks file and concludes the import is server-side only. Entrypoints now go through the samenormalize_id. The cwd prefix checks also gained a trailing slash, since a sibling directory whose name extends the root's was treated as inside it.