Skip to content

Version Packages (next) - #398

Merged
ryansolid merged 1 commit into
nextfrom
changeset-release/next
Oct 8, 2026
Merged

ryansolid merged 1 commit into
nextfrom
changeset-release/next

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to next, this PR will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

next is currently in pre mode so this branch has prereleases rather than normal releases. If you want to exit prereleases, run changeset pre exit on next.

⚠️⚠️⚠️⚠️⚠️⚠️

Releases

@solidjs/vite-plugin@3.0.0-next.48

Minor Changes

  • 1702a19: BREAKING: start-mode middleware is event-first, (event, next) => Response | Promise<Response>, with the request at event.request. The plugin composes the chain itself. next() takes no arguments — assign event.request before calling it to substitute the request downstream; next(request) throws a migration error. Per-request render inputs live on the event, set before next() (the render runs inside it): event.nonce (a string or { script, style }) and event.renderMode ('stream' | 'async'). handleRequest(request, { nonce, renderMode }) is seeded onto the event before the chain and wins over a middleware write, then the event field, then static start.renderMode, then 'stream'. Invalid host options reject the call before the chain. Generated entries pass event.nonce to renderToStream; authored entries must forward the context.nonce the handler passes them. The injected client-entry script, redirect fallback, dev head, dev styles, and (when there is a style nonce) a <meta property="csp-nonce"> carry it too. The start.renderMode module form, which only shipped in 3.0.0-next prereleases, is removed — a path is a config error pointing at event.renderMode in middleware. The static 'stream' | 'async' shorthand stays. A nonce set while prerendering the client-mode shell is not baked into dist/client/index.html (the build warns). In dev, changing event.nonce or event.renderMode after the render has read them warns.

Patch Changes

  • c41d013: Chunk and asset names derived from file names no longer carry runs of dots. A catch-all route module such as [...404].tsx built to _...404_-<hash>.js, and hosts, CDNs or middleware that reject any URL containing .. refused that chunk, so the lazy route failed to hydrate. Builds now run the configured output.sanitizeFileName (or the bundler default) and then collapse every run of dots in the last segment of the name to one: the chunk becomes _.404_-<hash>.js. Directories are left alone: with preserveModules they are part of the name. The server build is named the same way, so the asset URLs it writes into server-rendered markup keep pointing at the files the client build wrote. A custom sanitizeFileName still runs, with the collapse applied after it, whether it comes from the config or from another plugin's outputOptions hook; sanitizeFileName: false is left alone. Fixes Catch-all route chunks are named _...404_-<hash>.js; the .. trips path-traversal guards and breaks the lazy preload #391.
  • 9f5b744: Use the resolved client and server build directories when prerendering client-mode shells and serving preview requests. Preserve the SSR service for host build orchestrators such as Nitro, including client mode without server functions, while standalone client builds still produce only static output.
  • 970bc19: handleRequest(request, { nonce }) accepts the { script, style } form of @solidjs/web's CSPNonce and uses its script value for the scripts the handler writes: the injected client-entry tag and the post-flush redirect fallback. A pair used to throw TypeError: value.replace is not a function. A value outside CSPNonce (anything but a string or a { script, style } object with both keys, each a non-empty string or false) now rejects the call up front with an error naming the option, before the middleware chain runs; an empty value (undefined, null or '') still means no nonce. The option is now declared in the virtual:solid-ssr-handler types.
  • ec428e1: A hand-written lazy() moduleUrl with a leading slash (lazy(() => import("./Page"), undefined, "/src/Page.tsx")) now resolves like the project-relative key src/Page.tsx (lazy() moduleUrl with a leading slash never resolves: dev emits //src/…, the build manifest lookup misses #390). In dev the asset resolver built a protocol-relative //src/Page.tsx URL, so the preload failed and hydration fell back to a client render; in production the virtual:solid-manifest lookup missed, no client assets or root module map were emitted, and hydration threw "was not preloaded before hydration". The dev resolver (in-process, HTTP bridge, and the generated fallback) now strips the leading slash before building the URL and walking the module graph, and the baked build manifest answers slash-prefixed lookups through non-enumerable aliases, so for…in, Object.keys, and JSON consumers see the manifest unchanged.
  • efdaf56: The Start handler now settles failures that escape the middleware chain instead of letting them reject to the host. A thrown Response, or the Response a thrown respond() envelope carries, becomes the response in dev and production, so throw redirect() works from middleware. In a production build any other failure (a middleware throw, a start.setup or start.renderMode module failure) is reported once to the configureServerErrors hook as { kind: 'render', handling: 'failed' } with the request event, or logged with console.error without a hook, and answered with a bodyless 500. That 500 keeps the headers and cookies written to the request event while the response head is still open, that is, unless next() already returned a rendered page. In dev those failures still reject, so the dev server sees the original error. An invalid renderMode passed to handleRequest still rejects the call. A client-mode build now fails when prerendering the shell answers a non-2xx status, instead of writing that response to index.html.
  • c3a47d5: The dependency scanner settings now reach every environment, not just client (Vite 8: dep scan JSX is only set for the client environment, so ssr scans (e.g. Cloudflare) fail on react/jsx-dev-runtime #387). Vite seeds only the client environment from the top-level optimizeDeps, so an ssr (or other server) environment with discovery turned back on — as @cloudflare/vite-plugin does for workerd SSR — scanned Solid TSX with Rolldown's default React automatic runtime. The scan failed on an unresolvable react/jsx-dev-runtime and pre-bundling was skipped for that environment, which showed up as duplicate Solid instances in the app. configEnvironment now gives non-client environments the classic scanner JSX runtime (unless the app set its own per-environment transform.jsx), the .tsrx extension, and the tsrx scan plugin.
  • 9548326: The build now defines __SOLID_SERVER_COMPONENTS__ so libraries can drop server-component-only client code (Define __SOLID_SERVER_COMPONENTS__ at build time so libraries can drop server-component-only client code #396). The value is "true" when serverFunctions.components is set (including 'external') and "false" otherwise, and it is always defined — an absent identifier cannot be eliminated. It is set on Vite's define (build, and dev source via /@vite/env) and on every environment's optimizeDeps.rolldownOptions.transform.define, because the optimizer ignores top-level define and only the client environment inherits top-level optimizeDeps. A user-provided define value wins, and so does a value already set on that environment's optimizer.
  • 2a714d4: With serverFunctions on, the dev server now pre-bundles the server-function client runtime even without components (@solidjs/web/server-functions, or runtime.client when it names a package), so a cold cache no longer re-optimizes and reloads on the first "use server" module. In Vitest browser mode that reload showed up as "Vite unexpectedly reloaded a test".
  • 5062f90: Require solid-js / @solidjs/web 2.0.0-rc.14 (peer floor) and compile with @solidjs/compiler / @solidjs/babel-plugin rc.14 — runtime and compiler move in lockstep. rc.14 treats a lowercase on* name (onclick) as a plain attribute everywhere (both compilers, spread/assign, and the server spread walk); only on followed by an uppercase letter is an event handler, and a function handed to a lowercase on* attribute is escaped rather than bound. Server-component frame markup also moved: refetched content lands at the transition's commit. With the old ^2.0.0-rc.13 floor an existing lockfile could keep an rc.13 compiler while the app's runtime moved to rc.14, so compiled output and the frames runtime would disagree; the floor bump closes that window.
  • ae8a8b0: Under vite dev the SSR environment now inlines seroval and seroval-plugins next to solid-js and @solidjs/web. Both ship a dist/dev build behind the development condition, and @solidjs/web imports both. Left external, seroval-plugins loaded through Node and its own import "seroval" resolved to the prod copy, while the inlined @solidjs/web got the runner's dev copy. Seroval detects streams with instanceof Stream, so the Stream that ReadableStreamPlugin builds from one copy was rejected by the other copy's serializer. This broke server components (serverFunctions: { components: true }) in dev when a component resolved after the shell flush (for example after an await in the server function): its sc:live ReadableStream failed with "Seroval caught an error during the parsing process … cannot be parsed/serialized", the <Loading> boundary contained the error, and the component only rendered on the client. Builds were unaffected because they bundle a single copy. A host that sets noExternal: true and Vitest projects are left alone, as before.

@github-actions
github-actions Bot force-pushed the changeset-release/next branch 6 times, most recently from f24c0ab to 5291104 Compare October 8, 2026 20:29
@ryansolid ryansolid mentioned this pull request Oct 8, 2026
4 tasks
@github-actions
github-actions Bot force-pushed the changeset-release/next branch from 5291104 to 96691bb Compare October 8, 2026 21:10
@github-actions
github-actions Bot force-pushed the changeset-release/next branch from 96691bb to 07ca4db Compare October 8, 2026 21:16
@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@solidjs/vite-plugin@398

commit: 07ca4db

@ryansolid
ryansolid merged commit 43d4071 into next Oct 8, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant