Changelog

Every release these kits have shipped, with the date it shipped. The most recent release is at the top of each list.

27
dated releases
144
individual changes
3
kits
33 days
26 Aug 2026 – 27 Sep 2026

Why this page exists

Starter kits rot. Dependencies get CVEs, framework majors land, and a kit that stopped shipping is a kit you will be maintaining yourself in six months. The free alternative most people compare against,CMSaasStarter, has never published a tagged release at all, and its most recent commit is dated 21 March 2026 — check that link if you want to confirm it. Nothing here is a claim about what that project is doing; it is the reason a buyer should ask any vendor for a dated changelog, and then read this one.

Multi-tenant SvelteKit Starter

10 releases · 53 changes · latest v0.2.9 on27 Sep 2026

  1. v0.2.9

    5changes

    Added

    • `tests/csrf-cookie.test.ts` — real client-bundle exposure guard. Walks every module SvelteKit also runs in the browser (`.svelte`, `+page.ts`, `+layout.ts`) and fails if any of them imports `$lib/server/*` auth code or reads the session cookie from `document.cookie`. This replaces a test that was *named* for this guard while asserting only `maxAge`.

    Fixed

    • A test whose name claimed a security property it did not check. `never exposes the session token to a public module` asserted `maxAge > 0`. Split into `gives the session cookie a positive lifetime` (what it actually checked) and the new, real exposure guard.

    Changed

    • The `sameSite` pin is renamed `pins sameSite to 'lax' so the documented threat model stays true`. The previous name claimed the test "documents the limits" of `lax`; it never did. It pins the *premise* of the documented threat model (change the cookie option and the analysis stops describing the code, so fail and revisit). The two documented limits themselves are browser behaviour and are not unit-tested, and the test's docblock now says so.

    Notes

    • 307 tests across 14 suites, coverage 98.84 / 95.62 / 100 / 99.17. `svelte-check` clean.
    • The exposure guard is falsifiable: adding a `.svelte` file that imports `$lib/server/auth` makes it fail with the offending path in the message.
  2. v0.2.8

    3changes

    Added

    • **Dinh Fire Lamp theme** applied across the app UI and docs — Bạc Ngà (ivory) light default with an optional Rừng Đêm (forest-night) dark palette, tokenized per the shared design spec (Georgia serif headings, 18px radii, 60-30-10).

    Fixed

    • Light-mode `--faint` text color corrected to the spec value (`#97897a`; a dark-mode value had been used, dimming secondary text too far in light mode).

    Docs

    • Screenshot gallery refreshed — every capture re-taken against the themed live demo (owner dashboard, invite flow, seat updates, RBAC denial, audit trail; 298 tests).
  3. v0.2.7

    1change

    Docs

    • Suite tables completed to match the shipped 13 test files: `AGENTS.md`, `docs/testing.md`, and README status now list every suite (added `billing-edge-cases`, `rbac-boundary`, `service-integration`, `edge-cases`) with measured per-file counts (298 tests total).
  4. v0.2.6

    1change

    Tests

    • 298 tests (was 240): +58 new tests covering e2e billing flows (seat upgrades/downgrades, adapter failures, boundary conditions), RBAC boundary cases (cross-org isolation, rank escalation, hierarchy enforcement), full multi-step service-integration flows, and auth edge cases. Suite grown to 13 files.
  5. v0.2.4

    4changes

    Added

    • **Docker support**: `Dockerfile` (multi-stage Node 24 Alpine build) and `docker-compose.yml` with persistent SQLite volume for container deployments.
    • **Deployment docs**: `docs/deployment.md` — comprehensive deployment guide covering Docker, VPS, Cloudflare Pages, Vercel, Fly.io, and Postgres swap path.
    • **Usage-based billing guide**: `docs/ai-billing.md` — adapter pattern for AI token usage tracking, metered billing, and usage-based pricing.
    • **`.dockerignore`**: Build context exclusions for cleaner Docker builds.
  6. v0.2.3

    7changes

    Added

    • **Password strength validation**: `checkPasswordStrength()` now enforces uppercase, lowercase, and digit requirements (not just minimum length). Returns `{ ok, reasons }` for UI feedback.
    • **Session management**: `listSessions()`, `destroyAllSessions(exceptToken?)`, `cleanupExpiredSessions()` for security features like "log out everywhere" and session listing.
    • **Configurable session TTL**: `SESSION_TTL_DAYS` environment variable (default 30) for compliance scenarios requiring shorter sessions.
    • **Audit log export**: `exportAuditCsv()` and `exportAuditJson()` for compliance buyers who need to export their audit trail. CSV includes proper escaping; JSON includes ISO timestamps and parsed metadata.
    • **Billing guard**: `assertSeatAvailable()` now blocks `past_due` and `canceled` subscriptions from adding new seats.

    Fixed

    • **`createUser` error handling**: catch block now only catches unique constraint violations (`SQLITE_CONSTRAINT`, `SQLITE_CONSTRAINT_UNIQUE`, Postgres `23505`) instead of silently swallowing all DB errors as `email_taken`.

    Tests

    • 240 tests (was 204): +36 new tests covering password strength, session management, billing guard, error mapping with actual Error subclasses, audit export, and audit pagination edge cases.
  7. v0.2.2

    3changes

    Added

    • **Source documentation (TSDoc)**: every exported symbol on the public API surface now carries a doc comment — parameter/return/throws contracts, the RBAC hierarchy (`mayActOn`/`mayGrant`), the typed error codes, schema tables, and the swappable `BillingAdapter`/`RateLimiter` seams. Comments only — no behavior, signature, or formatting change; all 204 tests still pass.
    • **Generated public API reference**: `docs/api/` — a TypeDoc-generated reference for the full `src/lib/server` surface (auth, rbac, db, services, billing, http, ratelimit). Ships with the kit; regenerated from source so it cannot drift.
    • **Docs gate (CI + release pipeline)**: `npm run docs:api:check` in CI and a `gen-api-docs` check in the release pipeline now fail if any exported symbol goes undocumented or if `docs/api` falls out of sync with the source.
  8. v0.2.1

    7changes

    Added

    • **Audit suite**: `tests/audit.test.ts` — append-only writer (no update/delete path), metadata round-trip, null handling, newest-first pagination, history surviving member removal
    • **Billing suite**: `tests/billing.test.ts` — per-org seat counting, `assertSeatAvailable` (at-limit + no-subscription), mock adapter contract + `MOCK_PLAN_SEATS` env override
    • **Auth edge cases**: expired sessions rejected at read time; display-name fallback to email prefix
    • **Org/invite edges**: unique URL-safe slug generation, member-only org reads, multi-owner transfer guard, invite default TTL + recipient-email normalization, raw token never audited, member-revoke forbidden
    • **Documentation**: `docs/testing.md` — testing philosophy, suite layout, patterns, gotchas

    Changed

    • Test suite grown from 52 to **204 tests across 9 suites**
    • README/AGENTS/CLAUDE test counts and suite tables updated
  9. v0.2.0

    5changes

    Added

    • **Rate limiting**: Sliding-window failed-attempt limiter on login/signup - `RateLimiter` seam (`src/lib/server/ratelimit.ts`) - Configurable via `AUTH_FAILED_ATTEMPTS` (default: 5) and `AUTH_WINDOW_MS` (default: 900000ms/15min) - 429 response with approximate retry window - Pre-check before scrypt hashing (attacker pays the cost, not you) - Verified over HTTP: 400→400→429→recovery
    • 8 new unit tests for sliding-window semantics including eviction cap

    Fixed

    • **Redirect swallowing bug**: Form actions that redirect from inside try/catch now propagate SvelteKit's redirect instead of returning a false 500 after side effects have committed - Fixed at `errorToFail()` choke point - 4 regression tests added in `tests/http.test.ts` - Full flow proven over HTTP end-to-end

    Changed

    • Test count increased from 40 to 52
    • Rate limiter documented in `docs/architecture.md` with multi-instance guidance
  10. v0.1.0

    17changes

    Added

    • **Authentication**: Email+password with scrypt hashing, DB-backed revocable sessions, hashed session tokens
    • **Organizations**: Create, slug, owner bootstrap
    • **Invites**: Single-use hashed tokens, 7-day expiry, revoke, atomic claim
    • **RBAC**: `owner > admin > member` hierarchy with capability matrix enforced server-side on every action
    • **Billing**: `BillingAdapter` interface + deterministic `MockBillingAdapter` (seat limits enforced at join time)
    • **Audit log**: Append-only by construction (no UPDATE/DELETE path exists)
    • **Testing**: 40 passing tests covering auth, matrix, hierarchy, invite lifecycle, seat limits
    • **CI**: GitHub Actions workflow (install → test → check → build)
    • **Documentation**: Architecture, RBAC, billing, license docs
    • **Screenshots**: S1–S8 captured from running app
    • **Demo GIFs**: G1 (invite flow), G2 (RBAC denial)

    Design Principles

    • Server-side enforcement everywhere (UI hides controls, but every load/action re-checks)
    • Services are framework-free (import nothing from `@sveltejs/kit`)
    • Every mutating service call re-derives authority
    • Errors carry machine codes (`AuthError`, `RbacError`, etc.)
    • One error mapper (`errorToFail()`)
    • No ORM lock-in at service boundaries

Multi-tenant SvelteKit Starter product page · GitHub releases

SvelteKit + Supabase Starter

8 releases · 42 changes · latest v0.2.6 on20 Sep 2026

  1. v0.2.6

    6changes

    Added

    • **Shipped application UI** (`src/routes`): signup, sign-in, organizations, org workspace (members, invites, role changes, ownership transfer, leave), invite-link accept flow, and an audit-log view — all themed, wired to the existing services, and enforcing the RBAC matrix server-side on every action.
    • **Session cookie auth** (`src/hooks.server.ts` + `createAnonClient`/`signIn`/`setSessionCookie`/`clearSessionCookie` in `src/lib/server/supabase/client.ts`): the `session` cookie holds the Supabase refresh token; `hooks.server.ts` resolves `locals.user`/`locals.accessToken` per request with automatic rotation; sign-out revokes sessions server-side ("log out everywhere", `destroyAllSessions`).
    • **Audit reader** — `listAuditEntries` in `src/lib/server/audit.ts`: companion to the append-only writer, newest-first with a limit (used by the audit-log route). 4 new tests.
    • `/api/health` route: liveness + Supabase reachability check for deployments.

    Fixed

    • Made `npm run check` green for the first time (kit previously failed svelte-check): orgs join-row typing, `listUserSessions` typing gap on the installed Supabase client, `vite.config.ts` `defineConfig` import, `ThrowingAdapter`/`GenericThrowingAdapter` override signatures in `tests/billing-edge-cases.test.ts` (now 314 tests total, ≥ 95 % coverage maintained).

    Docs

    • Screenshot gallery refreshed — every capture re-taken from the themed live demo (org dashboard, landing, RBAC denial GIF, the 314-test run).
  2. v0.2.5

    1change

    Docs

    • Suite tables completed to match the shipped 12 test files: `AGENTS.md`, `docs/testing.md`, and README status now list every suite (added `auth`, `billing-edge-cases`, `rbac-boundary`, `service-integration`, `edge-cases`, `smoke-extended`) with per-file coverage notes (310 tests total).
  3. v0.2.4

    1change

    Tests

    • 310 tests (was 208): +102 new tests covering e2e billing flows (seat upgrades/downgrades, adapter failures, boundary conditions), RBAC boundary cases (cross-org isolation, rank escalation, hierarchy enforcement), full multi-step service-integration flows, and auth edge cases.
  4. v0.2.3

    4changes

    Added

    • **Docker support**: `Dockerfile` (multi-stage Node 24 Alpine build) and `docker-compose.yml` with Supabase credentials for container deployments.
    • **Deployment docs**: `docs/deployment.md` — comprehensive deployment guide covering Docker, VPS, Cloudflare Pages, Vercel, and Fly.io.
    • **Usage-based billing guide**: `docs/ai-billing.md` — adapter pattern for AI token usage tracking, metered billing, and usage-based pricing.
    • **`.dockerignore`**: Build context exclusions for cleaner Docker builds.
  5. v0.2.2

    6changes

    Added

    • **Auth module** (`src/lib/server/auth.ts`): `AuthError`, `checkPasswordStrength()`, `createUser()`, `listSessions()`, `destroyAllSessions()`, `normalizeEmail()`, `MIN_PASSWORD_LENGTH`, `SESSION_COOKIE`.
    • **Password strength validation**: enforces uppercase, lowercase, and digit requirements (not just minimum length). Returns `{ ok, reasons }` for UI feedback.
    • **Billing guard**: `assertSeatAvailable()` now blocks `past_due` and `canceled` subscriptions from adding new seats.
    • **Billing adapter types**: `SubscriptionStatus`, `SubscriptionState`, `getSubscriptionState()` on the `BillingAdapter` interface.

    Fixed

    • **`createUser` error handling**: catch block now only catches Postgres unique constraint violations (`23505`) instead of silently swallowing all DB errors as `email_taken`.

    Tests

    • 208 tests (was 198): +10 new tests covering billing guard (past_due/canceled/active/trialing) and audit listing (offset, ordering).
  6. v0.2.1

    3changes

    Added

    • **Source documentation (TSDoc)**: every exported symbol on the public API surface now carries a doc comment — parameter/return/throws contracts, the RBAC hierarchy (`mayActOn`/`mayGrant`), typed error codes, and the service-role vs user-scoped (`RLS`) Supabase client split. Comments only — no behavior, signature, or formatting change; all 198 tests still pass.
    • **Generated public API reference**: `docs/api/` — a TypeDoc-generated reference for the full `src/lib/server` surface (rbac, audit, services, billing, supabase/client). Ships with the kit; regenerated from source so it cannot drift.
    • **Docs gate (CI + release pipeline)**: `npm run docs:api:check` in CI and a `gen-api-docs` check in the release pipeline now fail if any exported symbol goes undocumented or if `docs/api` falls out of sync with the source.
  7. v0.2.0

    5changes

    Added

    • **Service-level test suite** — 51 new tests across `tests/orgs-members.test.ts`, `tests/invites-seats.test.ts`, `tests/billing.test.ts`, `tests/audit.test.ts`, backed by an in-memory fake Supabase client (`tests/helpers/fake-supabase.ts`). No database or network needed; suite 24 → **198 tests**.
    • **Documentation**: `docs/architecture.md`, `docs/rbac.md`, `docs/billing.md`, `docs/testing.md`

    Fixed

    • **Seat limits now enforced at invite acceptance** — `acceptInvite` previously documented seat enforcement ("join time") but never called the billing adapter. It now counts the org's memberships and runs `billing.assertSeatAvailable(orgId, count)` before the single-use claim, so a full org never burns an invite it cannot honor.
    • **`createBillingAdapter` guards invalid `MOCK_PLAN_SEATS`** — a non-numeric value previously produced a `NaN` seat limit that silently allowed unlimited joins; it now falls back to the default (3).

    Changed

    • README/AGENTS/CLAUDE testing sections updated to the real suite layout and count
  8. v0.1.0

    16changes

    Added

    • **Authentication**: Supabase Auth (email+password, magic links, OAuth)
    • **Organizations**: Create, slug, owner bootstrap with Supabase RLS for tenant isolation
    • **Invites**: Single-use hashed tokens, 7-day expiry, revoke, atomic claim
    • **RBAC**: `owner > admin > member` hierarchy with capability matrix enforced server-side on every action
    • **Billing**: `BillingAdapter` interface + deterministic `MockBillingAdapter` (seat limits enforced at join time)
    • **Audit log**: Append-only by construction (no UPDATE/DELETE path exists)
    • **RLS policies**: Defense-in-depth tenant isolation at the database level
    • **Testing**: Comprehensive test suite covering auth, RBAC, invites, billing
    • **CI**: GitHub Actions workflow (install → test → check → build)
    • **Documentation**: Architecture, RBAC, billing, versioning docs

    Design Principles

    • Server-side enforcement everywhere (UI hides controls, but every load/action re-checks)
    • Services are framework-free (import nothing from `@sveltejs/kit`)
    • Every mutating service call re-derives authority
    • Errors carry machine codes (`AuthError`, `RbacError`, etc.)
    • One error mapper (`errorToFail()`)
    • RLS provides defense-in-depth alongside application-level RBAC

SvelteKit + Supabase Starter product page · GitHub releases

SvelteKit + Postgres Starter

9 releases · 49 changes · latest v0.1.8 on27 Sep 2026

  1. v0.1.8

    3changes

    Fixed

    • **The boot-time migration race is closed with a Postgres advisory lock.** `openDb()` and `scripts/migrate.ts` now take `pg_advisory_lock(8240173)` around the migrator, so replicas booting at the same moment serialise instead of both deciding the same migration is pending and one failing on `already exists`. - The key is a single exported constant, `MIGRATION_LOCK_KEY`, imported by both paths. Two separate keys would not exclude each other, leaving the CLI and a booting replica free to run at once — the exact race the lock exists to close. - The lock is held on a **dedicated connection**, not one drawn from the main pool. Reserving from the pool would hand back its only connection under `max: 1` (the test configuration) and the migration would wait forever for a connection that is itself holding the lock. - The DDL runs on the pooled client while the lock is held on its own connection. An advisory lock is a mutual-exclusion gate between migrators, not a per-connection guard on the statements, so this closes the window without tying the DDL to the lock session. - This is not redundant with the migrator's own transaction. Drizzle's `migrate()` does wrap each run in `session.transaction(...)`, which is what makes an interrupted run roll back cleanly — but two *concurrent* runs both read the applied-migrations table before either commits, and the transaction does not help there. - `src/lib/server/db/index.ts` — `MIGRATION_LOCK_KEY` + `migrateUnderLock()`; the `@remarks` on `openDb()` no longer says migrations are unsafe under multiple replicas, because that is no longer true. - `scripts/migrate.ts` — takes the same key, so `npm run db:migrate` excludes a booting replica.

    Tests

    • **273 tests, coverage 98.58% statements / 95.53% branches / 98.57% functions / 99.61% lines.** Two new suites, run against a live Postgres: - `tests/migration-lock.test.ts` — asserts a second connection genuinely cannot take the lock while the first holds it, and that release hands the lock over. A test that cannot fail proves nothing, so the blocking is measured, not assumed. - `tests/migration-lock-control.test.ts` — negative control: a *different* key is not blocked by ours. This is what makes the assertion above meaningful, since it separates "the lock blocked it" from "the connection was merely busy".

    Credit

    • The advisory-lock suggestion came from a reader comment on the dev.to boot-migrations post.
  2. v0.1.7

    2changes

    Tests

    • Unchanged: 262 tests, coverage 98.57% statements / 95.53% branches / 98.55% functions / 99.61% lines. No code behavior changed in this release.

    Docs

    • **The boot-time migrator's concurrency limit is now documented.** `openDb()` runs the Drizzle migrator on every connection open, which is safe for local dev, a single instance, or a preview deploy — but several instances booting concurrently against the same Postgres database can each decide the same migrations are pending and race, producing `column already exists` or a partially applied migration. This was nowhere stated, so buyers running 2+ replicas would have hit it undocumented. - `src/lib/server/db/index.ts` — a `@remarks` block on `openDb()` next to the `migrate()` call: the boot call is a safety net, and under multiple replicas you keep `npm run db:migrate` as the only writer and treat the boot call as a no-op. - `docs/deployment.md` §3 — a warning subsection with a deployment table (what to do per deployment shape) and the reason both mechanisms exist: the explicit pre-deploy step is the reviewed, ordered event; the boot-time call is the guarantee that no instance serves traffic against an unmigrated schema.
  3. v0.1.6

    7changes

    Added

    • `Tx` type export (`Parameters<Parameters<Db['transaction']>[0]>[0]`); `audit()`, `countActiveSeats()`, and `assertSeatAvailable()` accept `Db | Tx` so they can participate in a caller's transaction.
    • 3 concurrency tests against a real Postgres (`tests/edge-cases.test.ts`): last-seat race (exactly one winner, loser gets `seat_limit`, invite unclaimed), duplicate-member race (`already_member`, losing invite unclaimed), and FK-violation rollback (claim unwinds). Suite total: 262 tests; coverage 98.57% statements / 95.53% branches / 98.55% functions / 99.61% lines.

    Fixed

    • **Seat limits can no longer be oversold by concurrent invite acceptance.** `acceptInvite()` now runs the whole flow — per-org `SELECT … FOR UPDATE` row lock → seat check → single-use claim → membership insert → audit write — inside one `db.transaction()`. Previously the seat count was read outside any transaction, so two different invites accepted at the same instant could both observe "one seat free" and both commit a membership. Concurrent accepts for one org now serialize on the organization row; the conditional `UPDATE … WHERE accepted_at_ms IS NULL … RETURNING` claim remains the authoritative single-use gate. No `40001` retry loop is needed because the lock is always the transaction's first statement, so accepts queue instead of deadlocking.
    • Concurrent acceptance of two *different* invites by the same user now returns the domain error `already_member` (Postgres `23505` on `memberships_org_user_uq` is translated) instead of a 500, and the losing invite is left unclaimed by the rollback so it still works later.
    • Any failure inside the transaction (e.g. a foreign-key violation on the membership insert) now rolls back the invite claim — the link stays open instead of being burned.

    Docs

    • `docs/architecture.md` concurrency notes rewritten: the old "claim+count could be wrapped in one transaction" limit is gone; the new limits (external billing call inside the lock; Postgres-only — D1 `batch()` and PostgREST have no interactive transactions) are documented instead.
    • README/AGENTS.md/docs/testing.md updated to v0.1.6 · 262 tests; TypeDoc reference regenerated (`audit` signature, new `Tx` alias). Screenshot S6 still shows the pre-0.1.6 run and is regenerated by the standing screenshot pipeline at release.
  4. v0.1.5

    3changes

    Added

    • **Dinh Fire Lamp theme** applied across the app UI and docs — Bạc Ngà (ivory) light default with an optional Rừng Đêm (forest-night) dark palette, tokenized per the shared design spec (Georgia serif headings, 18px radii, 60-30-10).

    Fixed

    • Light-mode `--faint` text color corrected to the spec value (`#97897a`; a dark-mode value had been used, dimming secondary text too far in light mode).

    Docs

    • Screenshot gallery refreshed — every capture re-taken against the themed live demo (org dashboard, RBAC denial GIF, audit; 259 tests).
  5. v0.1.4

    1change

    Docs

    • Suite tables completed to match the shipped 13 test files: `AGENTS.md`, `docs/testing.md`, and README status now list every suite (added `billing-edge-cases`, `rbac-boundary`, `service-integration`, `edge-cases`) with per-file coverage notes (259 tests total).
  6. v0.1.3

    1change

    Tests

    • 259 tests (was 206): +53 new tests against a real Postgres test database covering e2e billing flows (seat upgrades/downgrades, adapter failures, boundary conditions), RBAC boundary cases (cross-org isolation, rank escalation, hierarchy enforcement), full multi-step service-integration flows, and auth edge cases.
  7. v0.1.2

    2changes

    Added

    • **Usage-based billing guide**: `docs/ai-billing.md` — adapter pattern for AI token usage tracking, metered billing, and usage-based pricing.
    • **`.dockerignore`**: Build context exclusions for cleaner Docker builds.
  8. v0.1.1

    9changes

    Added

    • **Password strength validation**: `checkPasswordStrength()` enforces uppercase, lowercase, and digit requirements (not just minimum length). Returns `{ ok, reasons }` for UI feedback.
    • **Session management**: `listSessions()`, `destroyAllSessions(exceptToken?)` for security features like "log out everywhere".
    • **Billing guard**: `assertSeatAvailable()` now blocks `past_due` and `canceled` subscriptions from adding new seats.

    Fixed

    • **`createUser` error handling**: catch block now handles `DrizzleQueryError.cause.code` for Postgres unique constraint violations (`23505`) instead of silently swallowing all DB errors as `email_taken`.

    Tests

    • 206 tests (was 194): +12 new tests covering billing guard (past_due/canceled/active/trialing), audit pagination (offset, limit=0, ordering), and error mapping with actual Error subclasses.

    Planned

    • Real merchant-of-record billing adapter (Lemon Squeezy / Paddle) behind the existing `BillingAdapter` seam
    • JSONB metadata columns on audit_log / memberships (upgrade path documented in `docs/deployment.md`)
    • GIN full-text search over the audit log (tsvector, documented in `docs/deployment.md`)
    • Drizzle read/write split configuration for read replicas (documented in `docs/deployment.md`)
  9. v0.1.0

    21changes

    Added

    • **Authentication**: Email+password with scrypt hashing, DB-backed revocable sessions, hashed session tokens (raw token never persisted)
    • **Rate limiting**: Sliding-window failed-attempt limiter on login/signup — `RateLimiter` seam, `AUTH_FAILED_ATTEMPTS`/`AUTH_WINDOW_MS` env, 429 with approximate retry window, cheap pre-check before scrypt
    • **Organizations**: Create, unique URL-safe slug, owner bootstrap, member-only reads
    • **Invites**: Single-use hashed tokens, 7-day expiry, revoke, atomic conditional-UPDATE claim, optional recipient-email note
    • **RBAC**: `owner > admin > member` hierarchy with capability matrix, enforced server-side on every load/action; hierarchy rules (act downward, grant strictly below, no self-modification, single-owner invariant)
    • **Billing**: `BillingAdapter` interface + deterministic `MockBillingAdapter` (seat limits enforced at join time via `assertSeatAvailable`)
    • **Audit log**: Append-only by construction — no UPDATE/DELETE path exists anywhere
    • **Postgres port**: Drizzle Postgres schema (`uuid` primary keys, bigint epoch-ms timestamps, Postgres indexes) with the `postgres.js` driver; service layer untouched from the SQLite starter (swap the driver, keep the services)
    • **Migrations**: Checked-in Drizzle SQL migration (`drizzle/0000_init.sql`), applied automatically at boot via `migrate()`; `npm run db:migrate` for on-demand application
    • **Connection pooling**: Pool sized by `PG_MAX_CONNECTIONS`; PgBouncer/Supavisor guidance in `docs/deployment.md`
    • **RLS (opt-in)**: `rls/0010_rls_policies.sql` — Row-Level Security policies for all tenant tables with `FORCE RLS`, per-request `app.current_user_id` GUC pattern, documented as fail-closed defense-in-depth
    • **Local Postgres**: `docker-compose.yml` with Postgres 16 (dev :5433 + test :5434 databases)
    • **Testing**: 194 tests across 9 suites against a real Postgres test database (per-worker isolated schema + per-test truncation), `fileParallelism: false`
    • **Documentation**: Architecture, RBAC, billing, testing, deployment (providers, pooling, RLS, optional upgrades), versioning
    • **Repository hygiene**: `AGENTS.md`, `CLAUDE.md`, `CONTRIBUTING.md`, `.github` templates (CI with Postgres 16 service container, release pipeline), EULA (`LICENSE`)

    Design Principles

    • Server-side enforcement everywhere (UI hides controls, but every load/action re-checks)
    • Services are framework-free (import nothing from `@sveltejs/kit`)
    • Every mutating service call re-derives authority
    • Errors carry machine codes (`AuthError`, `RbacError`, etc.); one error mapper (`errorToFail()`)
    • No ORM lock-in at service boundaries — same service layer runs on SQLite or Postgres
    • Tenancy enforced in the app layer by default; RLS shipped as opt-in hardening

SvelteKit + Postgres Starter product page · GitHub releases

How to check this page

These numbers are not maintained by hand. The build reads theCHANGELOG.md of each kit in the repository and renders what it finds, so a release cannot appear here without an entry behind it, and an edited entry changes this page. AKeep a Changelog file is the source of truth, not this rendering of it.

If a kit here is stale, that is a fact you can see, and it is the same kind of fact as a competitor's last release date. That is the point: you should be able to tell without asking.

Get in touch

Questions about the product, team licenses, or anything else? We'll aim to respond within 48 hours.

Max 2000 characters

Stored in our own database — no third party. Deleted on request.