fix: only require svelte-trusted-html trusted-types policy when client code ships - #16928
Merged
elliott-with-the-longest-name-on-github merged 3 commits intoAug 25, 2026
Conversation
Signed-off-by: will Farrell <willfarrell@proton.me>
|
Install the latest version of pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/342c98db79bf71ea4a82440865f6dd31df678a4eOpen in Note This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed. |
🦋 Changeset detectedLatest commit: 342c98d The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
6 tasks
elliott-with-the-longest-name-on-github
left a comment
Contributor
There was a problem hiding this comment.
This seems reasonable, but needs a test that proves it works and prevents us from regressing it in the future.
Signed-off-by: will Farrell <willfarrell@proton.me>
Contributor
Author
|
done. tests added. |
elliott-with-the-longest-name-on-github
approved these changes
Aug 25, 2026
elliott-with-the-longest-name-on-github
merged commit Aug 25, 2026
ff8cdd4
into
sveltejs:version-3
36 of 37 checks passed
Contributor
|
Thank you! |
Rich-Harris
pushed a commit
that referenced
this pull request
Aug 26, 2026
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to version-3, this PR will be updated.⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ `version-3` is currently in **pre mode** so this branch has prereleases rather than normal releases. If you want to exit prereleases, run `changeset pre exit` on `version-3`.⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ # Releases ## @sveltejs/adapter-bun@1.0.0-next.2 ### Major Changes - breaking: require Bun 1.4, which routes `HEAD` to `GET` handlers and settles `stop()` after a force close ([#16880](#16880)) ### Patch Changes - fix: build apps that use server instrumentation ([#16898](#16898)) - Updated dependencies [[`ff8cdd4`](ff8cdd4), [`723572c`](723572c), [`3b8e034`](3b8e034), [`f2c5102`](f2c5102), [`c66a6ed`](c66a6ed), [`428e5ef`](428e5ef)]: - @sveltejs/kit@3.0.0-next.26 ## @sveltejs/adapter-node@6.0.0-next.11 ### Patch Changes - chore: remove polka, attach the handler to the http server directly ([#16907](#16907)) - Updated dependencies [[`ff8cdd4`](ff8cdd4), [`723572c`](723572c), [`3b8e034`](3b8e034), [`f2c5102`](f2c5102), [`c66a6ed`](c66a6ed), [`428e5ef`](428e5ef)]: - @sveltejs/kit@3.0.0-next.26 ## @sveltejs/kit@3.0.0-next.26 ### Patch Changes - fix: only require the `svelte-trusted-html` trusted-types policy when client-side code is shipped, allowing builds where all pages have `csr: false` ([#16928](#16928)) - chore: stop externalizing `cookie` dependency during build ([#16936](#16936)) - fix: preserve metadata on streamed page responses ([#16935](#16935)) - fix: error on server-only imports reachable from hooks or service worker files outside the project root ([#16912](#16912)) - fix: copy worker files emitted by the server build to the client output directory ([#16929](#16929)) - fix: Reject all pending query promises when a query fails before resolving with a value for the first time ([#16890](#16890)) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, setting csp.directives['require-trusted-types-for']: ['script'] without including 'svelte-trusted-html' in trusted-types threw during config validation. This blocked builds of apps where every page has csr: false — those apps ship no client-side code, so the policy is never used.
The check now runs at build time instead, reusing the same statically-analysed page options that decide skip_client_build. If any page ships client code (or its csr option can't be statically analysed), the original error still throws; if all pages have csr: false, the build proceeds.
Note: since the analysis only runs during build, vite dev no longer surfaces the missing policy at startup.
Please don't delete this checklist! Before submitting the PR, please make sure you do the following:
Tests
pnpm testand lint the project withpnpm lintandpnpm checkChangesets
pnpm changesetand following the prompts. Changesets that add features should beminorand those that fix bugs should bepatch. Please prefix changeset messages withfeat:,fix:, orchore:.Edits