Skip to content

Update vulnerable Svelte build toolchain dependencies #309

Description

@PathGao

A complete lockfile audit still reports high-severity findings in the SvelteKit/Svelte/Vite build toolchain: SvelteKit, Svelte, Vite, Rollup, PostCSS, Picomatch, and Devalue.

Although the release bundle is client-side, these packages process project input during development and release builds. Update within the existing Svelte 5, SvelteKit 2, and Vite 6 major lines, regenerate the lockfile, and verify npm ci, checks, tests, production build, and a clean full audit.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions