Skip to content

chore: bump sv and sv-utils devdep and peer - #7

Open
paoloricciuti wants to merge 2 commits into
mainfrom
bump-sv-utils-dep
Open

paoloricciuti wants to merge 2 commits into
mainfrom
bump-sv-utils-dep

Conversation

@paoloricciuti

Copy link
Copy Markdown
Collaborator

We released sv@1.0.1 yesterday together with SvelteKit 3.

This bumps the peerdep and the devdep. I've also asked Astra to add a compatibility test for older versions just to be safe, but I'm not sure it's really necessary (cc @jycouet).

@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​sveltejs/​sv-utils@​0.3.3 ⏵ 1.0.098 +1710082 +196 +1100
Updatedsv@​0.17.1 ⏵ 1.0.199 +410082 +197100

View full report

@jycouet

jycouet commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smart to write it like this "sv": "^1.0.0 || >=0.13.1 <1.0.0" to avoid warnings (>=0.13.1 <2 would be nicer, but woud get sv warning today).

Yes, it looks good to me like this. 👍

Comment thread tests/compatibility.test.mjs Outdated
@@ -0,0 +1,95 @@
import assert from 'node:assert/strict'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why *.mjs? Afaik, since the repo is ESM, all .js is treated as ESM.

Comment thread tests/compatibility.test.mjs Outdated
new URL('../.test-output/', import.meta.url),
)
fs.mkdirSync(testDirectory, { recursive: true })
process.env.MSW_VERSION = '3.0.0'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it safe to hard-code this?

Comment thread tests/compatibility.test.mjs Outdated
import assert from 'node:assert/strict'
import fs from 'node:fs'
import path from 'node:path'
import { test } from 'node:test'

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we please use Vitest since the project already has it? I see node:test providing us no benefits here, only diverging the tooling.

@kettanaito

Copy link
Copy Markdown
Member

Looks good! Thank you for opening this, @paoloricciuti. Let me know if it's safe to merge.

@paoloricciuti

Copy link
Copy Markdown
Collaborator Author

Looks safe to merge...didn't do it because I'm not familiar with the publishing setup and didn't want to mess something 😅

@kettanaito

Copy link
Copy Markdown
Member

Does this have to be published? Let me know, I'll adjust the conventional commit name for this PR then.

@paoloricciuti

Copy link
Copy Markdown
Collaborator Author

Does this have to be published? Let me know, I'll adjust the conventional commit name for this PR then.

Yup, the dependency is bundled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants