chore(deps-dev): bump svelte from 3.50.1 to 5.53.5 in /examples/svelte/localized-sveltekit#4324
Conversation
Bumps [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte) from 3.50.1 to 5.53.5. - [Release notes](https://github.com/sveltejs/svelte/releases) - [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG-pre-5.md) - [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.53.5/packages/svelte) --- updated-dependencies: - dependency-name: svelte dependency-version: 5.53.5 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
| "prettier": "^2.6.2", | ||
| "prettier-plugin-svelte": "^2.7.0", | ||
| "svelte": "^3.44.0", | ||
| "svelte": "^5.53.5", |
There was a problem hiding this comment.
Svelte 5 upgrade breaks incompatible v3/v4 toolchain ecosystem
High Severity
Bumping svelte from v3 to v5 without upgrading the rest of the toolchain will break the project. eslint-plugin-svelte3 requires svelte ^3.2.0, svelte-hmr@0.15.3 requires svelte ^3.19.0 || ^4.0.0, and @sveltejs/vite-plugin-svelte-inspector@1.0.4 requires svelte ^3.54.0 || ^4.0.0 — none of which match v5. @sveltejs/kit@1.30.4 is SvelteKit 1.x, which was not designed for Svelte 5. The companion packages (@sveltejs/kit, @sveltejs/vite-plugin-svelte, eslint-plugin-svelte3, prettier-plugin-svelte) all need to be updated to Svelte 5-compatible versions.
Additional Locations (2)
| "devDependencies": { | ||
| "@sveltejs/adapter-auto": "*", | ||
| "@sveltejs/kit": "next", | ||
| "@sveltejs/kit": "*", |
There was a problem hiding this comment.
Lockfile version specifier mismatches package.json for @sveltejs/kit
Medium Severity
The lockfile's root package metadata (packages[""]) now lists @sveltejs/kit as "*", but package.json still specifies "@sveltejs/kit": "next". These are semantically different — "next" resolves to a specific dist-tag on npm, while "*" matches any version. This mismatch means the lockfile is out of sync with package.json, which can cause npm install to behave inconsistently or regenerate the lockfile unexpectedly.
|
View your CI Pipeline Execution ↗ for commit 8dcde12
☁️ Nx Cloud last updated this comment at |


Bumps svelte from 3.50.1 to 5.53.5.
Release notes
Sourced from svelte's releases.
... (truncated)
Changelog
Sourced from svelte's changelog.
... (truncated)
Commits
ed14b49Version Packages (#17802)0df5abcMerge commit from fork0298e97Merge commit from fork96fd3ceVersion Packages (#17786)1b3e660fix: prevent flushed effects from running again (#17787)673a1abfix: set server context after async transformError (#17799)3a28979fix: handle default parameters scope leaks (#17788)fcdc028fix: hydrate if blocks correctly (#17784)97f3ac5Version Packages (#17775)7deedc5fix: render:catchof#awaitblock with correct key (#17769)Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for svelte since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Medium Risk
Major Svelte upgrade (v3→v5) can break the SvelteKit example build/runtime and introduces a higher Node.js minimum (>=18). Lockfile dependency range changes (e.g.,
@sveltejs/kitrecorded as*) could cause non-deterministic installs if not aligned withpackage.json.Overview
Upgrades the
examples/svelte/localized-sveltekitdev dependencysveltefrom^3.44.0/3.50.1to^5.53.5and regeneratespackage-lock.jsonaccordingly (new transitive deps andsveltenow requiring Node>=18).The lockfile also changes how SvelteKit deps are recorded at the root (e.g.,
@sveltejs/kit/@sveltejs/adapter-autoshown as*instead ofnext), which may affect install reproducibility if it diverges frompackage.json.Written by Cursor Bugbot for commit 8dcde12. This will update automatically on new commits. Configure here.