mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 10:55:06 +03:00
docs/ssr-reference
37459
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
edafa1c1fc | docs(reference): add @supabase/ssr API reference | ||
|
|
b82dec4ef1 |
fix(studio): polish advisor attention indicator quirks (#47714)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix / UI polish. ## What is the current behavior? - The Advisors sidebar attention dot drifts 1–2px sideways on hover-expand, because its `left` offset was tied to the expanded state while the nav icon only shifts when the sidebar is persistently open. - When the Advisor Center header button is selected while in a critical state, it keeps a destructive outline instead of matching the other header circles (`bg-foreground`). ## What is the new behavior? - Sidebar attention dot offset follows the same condition as nav icon padding (persistently open), so it no longer drifts on hover-expand. - Selected Advisor Center button matches the other header circles (foreground fill, no destructive outline). Critical idle styling is unchanged aside from a destructive hover border. The critical dot is slightly lighter when selected in light mode so it still contrasts on the inverted fill. ## Additional context Earlier commits on this branch experimented with a shared `useAdvisorAttention` hook to sync the sidebar and header indicators. That was dropped: the sidebar Advisors route goes to project security/performance pages, while the header opens Advisor Center (including org notifications). Those surfaces should not share one attention definition — thanks Joshen for catching that. --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
620c9329cf |
fix(studio): prevent duplicate success toast on disk upgrade (#48097)
## Summary Fixes FE-3948: two success toasts were firing after a disk upgrade. Now the immediate toast is skipped when a disk resize is requested, since the polling effect already shows a completion toast once the resize is applied. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved disk settings update notifications to prevent premature success messages while configuration changes are still being applied. * Success confirmation now appears after disk resizing is fully completed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9f5b36fb3b |
docs(dart): OAuth server, custom providers, realtime heartbeat & explain reference updates (#47728)
> **Stacked on #47994** (`docs/dart-reference-categories-in-yaml`). Review/merge that first; GitHub will retarget this to `master` once it lands. ## What Adds Dart client library reference entries (`apps/docs/spec/supabase_dart_v2.yml`) for features shipped in [`supabase/supabase-flutter`](https://github.com/supabase/supabase-flutter) (parity with `supabase-js`). Rebuilt on the **new reference pipeline** (#47224 / #47994): each method's section comes from `category` / `subcategory` fields on its own YAML entry, with subcategory overviews as committed partials under `spec/reference/dart/v2/partials/`. As a result this PR no longer touches `common-client-libs-sections.json` or `supabase_js_v2.yml` (the earlier shared-nav id rename is unnecessary now that Dart no longer reads that file). ## Changes **Auth (OAuth 2.1 server)** — new **OAuth Server** section - `oauth.getAuthorizationDetails()`, `oauth.approveAuthorization()`, `oauth.denyAuthorization()` **Auth admin** — new **Custom Provider Admin** section - `admin.customProviders.listProviders/createProvider/getProvider/updateProvider/deleteProvider`, including `customClaimsAllowlist` **Realtime** - `onHeartbeat` - `onPostgresChanges` examples for the new pattern/negated filter operators, multiple filters, and column selection **Postgrest** - `explain()` `format` option (`ExplainFormat.text` / `.json`) ## Pipeline plumbing - New partials: `oauth-server.json`, `custom-provider-admin.json` - `generate-dart-reference.ts`: registers `oauth-server-api` and `admin-custom-providers-api` group-header ids in `HEADER_IDS` ## Source PRs supabase-flutter: #1499, #1516, #1517, #1519, #1526 ## Verification `pnpm codegen:references:new` builds cleanly and the nav renders the new **OAuth Server**, **Custom Provider Admin**, and Realtime **onHeartbeat** entries. ## Notes - `RealtimeChannelConfig.replicationReady` (#1526) is omitted since there is no reference slot for channel-config options. - The **OAuth Server** section also appears in #47971 (which adds `listGrants` / `revokeGrant`). Whichever lands second should drop the duplicate section header/partial and keep both sets of methods. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OAuth 2.1 server consent-flow methods for retrieving, approving, and denying authorization requests. * Added admin APIs for managing custom OIDC/OAuth providers. * Added Realtime heartbeat monitoring and advanced Postgres change filters. * Added text and JSON output options for query explanations. * **Documentation** * Expanded Dart API reference coverage across Auth, MFA, Passkeys, Database, Realtime, and Storage. * Added dedicated reference sections for OAuth Server and Custom Provider administration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8c511032b6 |
docs(dart): derive reference sections from spec YAML section headers (#47994)
## What Addresses @jeremenichelli's feedback that the Dart v2 reference required maintaining section metadata separately from the spec. The reference now derives every method's section from the spec YAML itself, with **no per-method metadata**. ## How Each **section-header** entry in `supabase_dart_v2.yml` carries the `category` and optional `subcategory` that every method after it inherits, up to the next header: - Existing subcategory headers gain a `category`/`subcategory`: `auth-mfa-api`, `passkey-api`, `admin-api`, `admin-passkey-api`, `file-buckets`, `using-modifiers`, `using-filters`. - New top-level category headers mark the sections that previously had no header: `auth-api`, `functions-api`, `database-api`, `realtime-api`. `generate-dart-reference.ts` walks the spec in order, tracking the current section from the most recent header, and tags each method's declaration with it. A method may still set `category`/`subcategory` explicitly to override, and the converter errors if a method appears before any header. ## Why this is less work - **Authoring a new method:** place it in the right section. No `category`/`subcategory` fields, no nav file edit. - **Adding a section:** one header entry (with `category`/`subcategory`) plus its overview partial. - `common-client-libs-sections.json` is not touched (it still drives the legacy-pipeline SDKs). ## Verification The generated navigation (`content/reference/dart/v2/sections.json`, `bySlug.json`) is **byte-for-byte identical** to the previous output. `pnpm codegen:references:new` writes 105 method declarations across 5 categories with no orphaned methods and no slug collisions. Supersedes the earlier per-method-`category` approach on this branch. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Improved Dart/Flutter API reference organization by leveraging spec-provided `category` and `subcategory` taxonomy for clearer grouping (Auth, Passkey, Edge Functions, Database, Realtime, Storage, and database modifiers/filters). * Updated reference generation to use structured in-spec section headers, resulting in more consistent published categorization and navigation. * **Bug Fixes** * Enhanced validation and error messaging for entries that can’t be assigned to a section/category, including clearer guidance on how to fix incomplete spec items. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
05d5da0340 |
chore: add ssl_enforcement_required for jit (#48032)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? chore / bug fix ## What is the current behavior? The new `ssl_enforcement_required` state is not handled ## What is the new behavior? Displays the correct message <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved temporary database access messaging when SSL enforcement is required. * Added a direct action to open database settings and enable SSL enforcement before activating temporary access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
24ce0ba5f8 |
chore: migrate repo to pnpm v11 (#48033)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / dependency tooling update. ## What is the current behavior? The repo is pinned to pnpm 10.24.0. Closes https://linear.app/supabase/issue/FE-3673/migrate-the-repo-to-use-pnpm-v11. ## What is the new behavior? The repo is pinned to pnpm 11.13.1, pnpm v11 workspace settings are migrated to `allowBuilds`, and the Studio Dockerfile installs pnpm 11.13.1. ## Additional context Validated with `CI=true mise exec node@22 -- pnpm install --frozen-lockfile`, `mise exec node@22 -- pnpm run typecheck`, and `mise exec node@22 -- pnpm run lint`; full Prettier check still fails on existing generated docs/router files outside this migration. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated tooling requirements (pnpm **11.13.1**, Node **>=22.13**) and aligned container build tooling accordingly. * Adjusted package manager behavior (scoped registry override, update notifications disabled) and workspace build/engine validation settings. * **Maintenance** * Updated `clean` scripts across apps/packages to remove only build/cache artifacts (no longer delete installed dependencies). * Reduced Turbo `clean` task output to **errors-only** for cleaner logs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bf0e84d55a |
fix(studio): make dev:studio-local work with the tanstack dev server (#48090)
With `STUDIO_FRAMEWORK=tanstack`, `pnpm dev:studio-local` ran Studio in platform mode against the management API instead of the local CLI stack (`/` redirected to `/org` instead of `/project/default`). Vite selects env files by *mode* while the Next dev server selects them via `NODE_ENV=test`, so the tanstack dev server never loaded `.env.test` and the developer's `.env.local` (`NEXT_PUBLIC_IS_PLATFORM="true"`) won. The shell `NODE_ENV=test` also gets inlined into the dev client bundle by Vite, flipping `API_URL` to the vitest-only MSW host. `vite dev --mode test` isn't a viable fix: TanStack Start's dev-server plugin treats mode `test` as "running under vitest" and skips installing its SSR middleware, so every route 404s. Instead, dev keeps mode `development` and overlays the env cascade named by `MODE` on top. **Changed:** - `dev:studio-local` now also sets `MODE=test` (the same knob `build:tanstack` / `e2e:setup:selfhosted` already use) - `vite.config.ts` dev server: loads the `MODE`-named env cascade for the `NEXT_PUBLIC_*` client defines and seeds it into `process.env` for SSR, without clobbering shell-provided values (matching `serve.js` semantics, and safe against TanStack's own load-env plugin since `loadEnv` gives existing `process.env` priority) - `vite.config.ts` dev server: remaps a shell `NODE_ENV=test` to `development` so it can't be baked into the client bundle (mirrors `next dev` behavior) Platform-mode `pnpm dev:studio` sets no `MODE`, so the overlay is a no-op there. Build (`--mode test`), `serve.js`, and vitest (separate `vitest.config`) paths are unchanged. ## To test - `supabase` CLI installed, then: `STUDIO_FRAMEWORK=tanstack pnpm dev:studio-local` - Visit http://localhost:8082 — it should redirect to `/project/default` (not `/org`) and the Default Project page should load with data from the local stack (network requests go to `localhost:8082/api/platform/...`, no `api.supabase.(com|green)` calls) - `pnpm dev:studio` (platform mode, tanstack) still behaves as before — redirects to `/org` - Next path regression check: plain `pnpm dev:studio-local` (no `STUDIO_FRAMEWORK`) still works <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved local Studio development and test-mode environment handling. * Prevented test settings from being incorrectly embedded in the client application. * Ensured environment values are loaded consistently across development and test scenarios. * **Chores** * Updated the local Studio development command to explicitly use test mode. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
13659ecc50 |
Chore/refactor observability layout menu (#48089)
## Context Just refactors `ObservabilityMenu` to retrieve the menu items via a hook + scaffold the Top for Postgres menu item No functional changes here <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a keyboard shortcut (`U`, then `C`) for quickly opening Observability Connections. * Improved observability navigation with feature-aware sections and consistent URL parameter preservation. * Custom reports are now sorted alphabetically and include available actions directly in the menu. * **Bug Fixes** * Improved handling of missing report details and duplicate or unsupported query parameters. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74a0848ea5 |
Update logos on homepage (#48087)
Updates logos on homepage and removes slider |
||
|
|
fa1e4c4bbf |
feat(studio): add ClickHouse replication destination (#46870)
Adds ClickHouse as a replication destination type in Studio.
- New ClickHouse option in the destination type selector, gated behind
the
`etlEnableClickHousePrivateAlpha` organization feature flag (off by
default).
- ClickHouse settings form: URL, user, password (optional), database,
and
- Client-side URL validation requires HTTPS and rejects URLs targeting
internal addresses (loopback, RFC 1918, link-local, CGNAT, IPv6
loopback/link-local/ULA, and IPv4-mapped/NAT64 forms). Server-side
validation remains authoritative.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## New Features
- Added **ClickHouse** as a replication destination option (private
alpha), including support in destination selection/panel, replication
diagram rendering, and destination icons.
- Introduced a ClickHouse destination form with fields for URL, user,
optional password (masked toggle), database, and engine selection.
- Added ClickHouse destination config handling for create/update flows,
with normalization and engine support.
## Tests
- Expanded unit tests to cover ClickHouse validation and destination
config building/normalization, including HTTPS-only and blocking
localhost/internal targets.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
|
||
|
|
8962308215 |
Add support for multiple custom auth providers in custom-content (#48030)
## Context Adds support for multiple custom auth providers in custom-content <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for multiple custom sign-in providers via a new plural configuration. * Updated the sign-in page to render all configured custom provider options while maintaining compatibility with the legacy single-provider setting. * Improved the custom provider button display to remove internal prefixes from provider names. * **Documentation** * Updated the configuration schema, examples, and sample data to document the new multi-provider setting. * Marked the legacy single-provider configuration as deprecated in favor of the plural option. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fc72a6b259 | fix(studio): preserve API report filter value casing so method filters match (#48056) | ||
|
|
c1d010a699 |
feat(docs) Add a SKILL to write stronger documentation and apply it to guides/api/securing-your-api (#48018)
Closes DOCS-1176 ## Summary This PR adds documentation-writing guidance for humans and agents, then applies it to the “Securing your API” guide. ## Changes - Add a documentation word list based on Google’s style guide and existing MDX lint rules. - Add a shared `docs-guides` Agent Skill with Cursor and Claude integration. - Expand contributing guidance for information types, procedures, chunking, links, admonitions, grammar, and terminology. - Restructure “Securing your API” into contextual and procedural sections. - Add section navigation, cross-references, transitions, and procedural outcomes. - Reduce repeated admonitions and improve scannability. ## Manual testing 1. Open `/docs/guides/api/securing-your-api` in Preview and compare to Live. https://docs-git-docs-restructure-api-supabase.vercel.app/docs/guides/api/securing-your-api 2. See that the content is improved and clear with no important context removed. 3. See the Admonitions that are no longer marked as admonitions. See the content still makes sense. 4. Review the diff of `CONTRIBUTING.md` and `WORD_LIST.md`. 5. See that you agree with the new rules and that they are clear. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated documentation-writing guidelines with clearer standards for structure, formatting, components, diagrams, terminology, and navigation. * Added a comprehensive word and style reference for consistent documentation language. * Reworked the API security guide with clearer guidance on grants, RLS, dedicated schemas, pre-request checks, rate limiting, and API keys. * Added documentation authoring workflow guidance, including validation and formatting steps. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c914163a06 |
Improve features search with relevance-based ranking (#48039)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature enhancement ## What is the current behavior? The features page filters search results by simple substring matching, treating all matches equally. Features are then sorted alphabetically regardless of search relevance. ## What is the new behavior? Search results are now ranked by relevance using a weighted scoring system: - Title matches starting with the search term score highest (5 points) - Title substring matches score 4 points - Subtitle matches score 2 points - Description matches score 1 point Results are sorted by relevance score (highest first), with alphabetical ordering as a tiebreaker. This ensures users see the most relevant features first when searching. ## Additional context The implementation adds: - `SEARCH_WEIGHT` constant defining the relevance weights for different match types - `getSearchScore()` function that calculates a feature's relevance to a search term - Updated filtering and sorting logic that uses relevance scoring The weights are carefully chosen so that any title match always ranks above features that only match in subtitle/description, improving search quality without requiring complex algorithms. https://claude.ai/code/session_01573vYv6WZhrboV14NQSuc4 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved feature search with relevance-based matching. * Search results now prioritize matches in feature titles, especially title prefixes, followed by subtitles and descriptions. * Results are displayed in relevance order for faster discovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6f19dfe18c |
fix(ui): bake explicit tabindex into interactive primitives (#47984)
## What kind of change does this PR introduce?
A11y fix for keyboard focus (esp. Safari), plus a lint rule to keep it
from regressing.
## What is the current behavior?
`Button` already defaults an explicit `tabIndex={0}` (#40458). Other
interactive primitives (Checkbox, bare triggers, etc.) still skip Tab
focus in Safari unless macOS Keyboard navigation is on. Raw `<button>`
call sites have no guardrail.
## What is the new behavior?
- Same explicit `tabIndex` default baked into Checkbox, Accordion
Trigger, Collapsible Trigger, Dropdown Menu / Popover / Dialog / Sheet /
Alert Dialog triggers, Table Head Sort, Command reset, sidebar actions,
and shadcn Button
- `supabase/require-explicit-tabindex` ESLint rule, ratcheted in Studio
(82 existing violations)
- Design-system accessibility docs list which primitives bake this in
Resolves [DEPR-621](https://linear.app/supabase/issue/DEPR-621)
## Additional context
### To test
Use **Safari** with macOS Keyboard navigation **off** (the default).
Chrome once for a sanity pass.
**Storage → Files bucket (list view) — Checkbox**
1. Open an empty folder (or one with only folders). Header “select all”
Checkbox is disabled and skipped by Tab — expected (`columnFiles.length
=== 0`).
2. Upload a file (e.g. an image). Header Checkbox enables.
3. Tab to it and toggle with Space. Row Checkboxes should also be
Tab-reachable.
**Storage → Analytics bucket → bucket details — Accordion Trigger**
On an Analytics bucket with no tables yet, Tab to the “Create your first
table via PyIceberg” Accordion Triggers and open/close with Enter/Space.
**Elsewhere (light smoke)**
- Bare Dropdown / Popover / Collapsible triggers still Tab + activate
- `*Trigger asChild><Button>` (Sheets, Dialogs, menus) still one Tab
stop; open/close fine
- Disabled controls stay out of the Tab order
### Later
Chip-away of the 82 raw Studio buttons (and remove exceptions from
rule). Prefer migrating those to `Button` from `ui` later.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Accessibility Improvements**
* Improved keyboard focus behavior across common interactive controls
(buttons, dialog/popover/dropdown/sheet triggers,
accordions/collapsibles, checkboxes, and sidebar actions).
* Disabled controls now default to `tabIndex={-1}`, while enabled
controls default to `tabIndex={0}`.
* Added explicit `tabIndex` handling for command reset and table sort
header controls.
* **New Features**
* Added a shared `getExplicitTabIndex` utility used by UI components to
standardize focus behavior.
* **Documentation**
* Updated accessibility guidance to clarify which components include
built-in focus/tabIndex handling and which require manual setup.
* **Developer Experience**
* Added an ESLint rule to enforce explicit `tabIndex` on raw button-like
elements, with corresponding baseline updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
50e9fedb20 |
feat(studio): finesse logs date picker range colours (#48019)
## What kind of change does this PR introduce? UI polish / bug fix for the shared Calendar range selection and Logs date picker. ## What is the current behavior? - Selected date ranges use opaque `brand-400` / `brand-500` fills that read too loud in light mode, with black text that is hard to read on darker endpoints. - Start/end days are squared off on the connecting edge without intentional outer rounding. - Outside days in a selected range are dimmed with `opacity-50`, which can tint the range wash incorrectly when a range starts in the prior month. - The large-range warning in `LogsDatePicker` is a full-bleed yellow banner that feels too heavy for the popover. - Time inputs show a clock icon that adds visual noise. ## What is the new behavior? - Range middle uses a softer `brand-200` wash; start/end stay on stronger brand fills with readable foreground text. - Start days round on the left (`rounded-l-md`), end days on the right (`rounded-r-md`); day hover keeps `rounded-md`. - Selected outside days and “today” no longer fight the range wash colours. - Large-range warning is quiet inline `text-warning` copy that wraps to the calendar column width. - Clock icon removed from `TimeSplitInput`. | Before | After | | --- | --- | | <img width="1096" height="1076" alt="CleanShot 2026-07-16 at 17 59 21@2x" src="https://github.com/user-attachments/assets/eac38022-ed92-4dbe-9932-55f7bf0af934" /> | <img width="988" height="1064" alt="CleanShot 2026-07-16 at 17 59 34@2x" src="https://github.com/user-attachments/assets/3dce30dd-9fd8-4da4-82b3-5663250a4ddc" /> | ## Additional context Shared `Calendar` changes apply anywhere range mode is used, not only logs. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Refined the date-picker popover layout for start/end controls with better fit and max-width handling. - Updated calendar day and range visuals (selection, outside states, rounding, and hover behavior) to reduce “ghost” styling and improve consistency. - Restyled the large-range warning to improve spacing and alignment. - Simplified the time-splitting input UI by removing the leading clock icon. - Adjusted the “Copy range” button feedback color for copied/pasted states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
77953e7a1f |
feat(studio): include enums and RLS policies in Schema Visualizer Cop… (#46189)
Extend the "Copy as Markdown" feature in the Schema Visualizer to include Custom Types/Enums and Row Level Security (RLS) Policies in the generated output. Closes https://github.com/orgs/supabase/discussions/46108 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — extend Copy as Markdown to include enums and RLS policies ## What is the current behavior? The "Copy as Markdown" function in the Schema Visualizer generates a SCHEMA.md that only includes tables, columns, and entity relationships. Custom Types/Enums and RLS Policies are missing, making the output an incomplete representation of the schema. Related: https://github.com/orgs/supabase/discussions/46108 ## What is the new behavior? The generated markdown now includes two additional sections: **Custom Types / Enums:** - Lists each enum type with its ordered permitted values - Filtered by the currently selected schema **RLS Policies:** - Grouped by table for self-contained readability - Includes policy name, command (SELECT/INSERT/UPDATE/DELETE/ALL), roles, action (PERMISSIVE/RESTRICTIVE), USING expression, and WITH CHECK expression **Example output:** ```markdown ## Custom Types / Enums ### `order_status` `pending` | `processing` | `shipped` | `delivered` ## RLS Policies ### `orders` | Policy | Command | Roles | Action | USING | WITH CHECK | |--------|---------|-------|--------|-------|------------| | `users_own_orders` | SELECT | authenticated | PERMISSIVE | `auth.uid() = user_id` | — | ``` ## Additional context - 3 files changed: `Schemas.utils.ts`, `SchemaGraph.tsx`, `Schemas.utils.test.ts` - New utility functions `getEnumsAsMarkdown()` and `getPoliciesAsMarkdown()` with unit tests - Reuses existing `useEnumeratedTypesQuery` and `useDatabasePoliciesQuery` hooks - No breaking changes — existing markdown output is preserved, new sections are appended <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * "Copy as Markdown" now includes enumerated types and database policies alongside existing schema/table content; policies are included with their rule details and grouped by table. * **Tests** * Added tests covering enum and policy markdown generation, including matching/non-matching schema cases and policy formatting. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46189?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
dba31df91d |
fix: scoped PAT creation form error messages are hidden (#48011)
## Problem When creating a new scoped PAT, if users didn't add at least one permission or have a misconfigured permission (no access selected), the form does not submit but no error message is shown. The UI looks broken. ## Solution This is because there's a zod validation happening but its messages are not displayed for permissions. The proper fix is to use react-hook-form field array. <img width="541" height="633" alt="image" src="https://github.com/user-attachments/assets/89cab58d-761e-4131-9bce-460625067f8a" /> <img width="540" height="594" alt="image" src="https://github.com/user-attachments/assets/ed95cee0-06b5-4233-9a23-6819fb0e1a17" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved permission selection and toggling behavior in the scoped access token flow. * Enhanced validation feedback for permission rows and action selections, keeping error states in sync after changes. * Updated error handling to surface permission-related messages more reliably. * **Refactor** * Reworked the permissions UI to use a more reliable control-based rendering approach for rows, selection changes, and error presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dc3c8684cc |
chore(deps): upgrade valtio to v2 (#48031)
Audited all proxy()/useSnapshot() usage against the v1→v2 migration guide; no breaking changes apply (no reused proxy() inputs, no promise-valued state, all consumers already client components). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the Valtio dependency to a newer version for improved compatibility. * **Bug Fixes** * Improved AI assistant persistence in IndexedDB so chat sessions reliably save (while keeping only the most recent 20 messages per chat). * Hardened tabs restoration from storage to fall back to fresh defaults when data is missing, invalid, or fails validation. * **Refactor** * Switched multiple studio panels to use fresh initial-state factories for initialization and reset reliability. * Updated advisor state so the derived notification filter count is no longer exposed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
06c2039d0b | test: Simplify setup (#48036) | ||
|
|
f19cb09b43 | feat(pipelines): Update product docs and UI copy (#47997) | ||
|
|
26b1fd9aab |
fix: keyboard navigation between docs tabs (#47778)
## Problem Keyboard navigation on docs tabs is confusing: - tab panels can be focused but without any indication that they are - code example buttons can be focused with keyboard but stay invisible - copy code button has no label and do not notify screen reader users about its status ## Solution - Make tab panels non focusable - Ensure buttons are visible when focused - Add a label to the copy code buttons - Add a live region for the copy code status ## How to test 1. Go to https://docs-git-gildasgarcia-docs-1156-cannot-keyboard-140a35-supabase.vercel.app/docs/guides/local-development/cli/getting-started 2. Go to a tab list with _Tab_ key 3. Verify you can choose the tab value with Arrow keys and select it with space 4. Tab again and verify you now have focused the code example first button and it is visible 5. Tab again and the copy code button should be focused and visible If you enable Voice over, clicking the copy code button should announce that the code has been copied <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Improved code block copy feedback so the “copied” state resets more reliably after interaction. * **Accessibility Improvements** * Code block controls now appear on keyboard focus (not just hover) and include an assistive live announcement when copying succeeds. * Enhanced code block semantics with clearer ARIA labeling. * Prevented tab panels from being reachable through normal tab navigation to reduce unintended focus stops. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3c6ef31959 |
feat: add User Filter to the unified logs (#47879)
Offshoot from https://github.com/supabase/supabase/pull/47743. [Linear issue](https://linear.app/supabase/issue/FE-3939/add-user-logs-filter-to-the-logs-page) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a `user` filter to Unified Logs with a user picker (email or ID). * Added “View user logs” actions from the Users table to jump to Unified Logs. * **Bug Fixes** * Updated Unified Logs searching so default log-type restrictions no longer block user-attributed results. * **UI Updates** * Unified Logs filter bar and reset behavior now include clearing the user filter. * Improved empty-state messaging when the selected user filter isn’t supported. * Refreshed highlighted styling in command list items. * **Tests** * Expanded coverage for user filter configuration and query edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com> Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
b9c8857394 |
fix(studio): TanStack route parity fixes from Next comparison audit (#48028)
Audited every TanStack route (~300 files) against its Next.js pages-router counterpart — layout wrapping, root providers, API routes, and deploy config — and fixed the divergences found. Same bug class as #48024, plus a few setup-level gaps. **Fixed (user-visible):** - `routes/__root.tsx` was missing `TimezoneProvider` + the `TimestampInfoProvider` bridge, so the stored timezone preference was silently ignored app-wide (timestamps always rendered in browser-local time) - `routes/_auth.tsx` wrapped all 10 auth pages in `AuthenticationLayout` (status banners + extra full-screen scroll container); in Next only `/sign-in` has it via getLayout. The parent is now a passthrough and sign-in wraps at the leaf - `routes/project/$ref/integrations.tsx` hardcoded `ProjectIntegrationsLayout`; the Next pages use `ProjectIntegrationsLayoutDispatch`, which switches to the Marketplace layout when that flag is enabled - `GlobalShortcuts` wasn't mounted, so the shortcuts-reference sheet (`?`) and its command-menu entry were unreachable - `routes/join.tsx` added a full-screen wrapper the Next page doesn't have (double `min-h-screen` around `InterstitialLayout`) **Fixed (behavior/config):** - ConfigCat flags lost the `plan` custom attribute, so plan-targeted flags could evaluate differently - `vercel.ts`: `api/server.js` had no `maxDuration` (Next sets up to 300s per route — stripe-sync, AI streaming); added the `/.well-known/vercel/flags` rewrite + JSON content-type (Flags Explorer endpoint previously fell through to the HTML shell); added `img`/`favicon` cache-control headers - `routes/api/v1/.../functions/$slug/body.ts` (bespoke reimplementation) dropped `apiWrapper`'s global catch — errors now get Sentry capture + the same 500 `{ error }` body - Reverted migration drift in `__root.tsx`: tooltip `delayDuration` 0 → Radix default (matching Next), `og:image` back to `supabase-og.png` - lodash → lodash-es for the whole SSR module graph (#48029, merged into this branch): the lodash CJS build's named-export interop yields non-functions under the Vite SSR module runner, which 500'd every page once `GlobalShortcuts` (or anything calling lodash during SSR render) mounted. An `options.ssr`-gated `resolveId` plugin in `vite.config.ts` serves `lodash-es` (same version, real ESM) to app source, workspace packages, and deps alike; client bundles untouched. Note: dev servers need a restart after pulling this (config change) Also corrected two stale route comments claiming the CLI/Stripe login pages inline `APIAuthorizationLayout` (they inline `InterstitialLayout`). **Not changed (audited, intentionally left):** - Redirect-only pages briefly flash `DefaultLayout` chrome under TanStack (normally unreachable — router-level redirects fire first) - Org pages inherit an inert `AppLayout` div via `routes/_app.tsx` (visually a no-op; Next org pages don't have it) - Adapter-level differences: framework 405s instead of Next's `Allow`-header JSON, `bodyParser.sizeLimit` not enforced on two routes, narrower favicon non-prod detection (commented as known) - Known pre-existing dev console error (also on Next master): closing the shortcuts sheet logs a setState-in-render warning — `@tanstack/react-hotkeys@0.10.0` calls `setOptions` in the `useHotkeySequence` render body, notifying `useHotkeyRegistrations` subscribers mid-render. Worth an upstream report/dep bump as a follow-up ## To test Verified on the local TanStack dev server via Playwright (all pass): - Set a timezone in the account dropdown → log timestamps show that timezone's row in the hover tooltip - `?` opens the shortcuts sheet; `⌘K` → "Show all keyboard shortcuts" does too - `/sign-in` still shows banners/window chrome; `/sign-up`, `/sign-in-sso`, `/forgot-password`, `/cli/login` render without the extra wrapper - `/project/<ref>/integrations` renders (legacy sidebar when marketplace flag off) - `/join` renders a single centered interstitial - `og:image` meta is `supabase-og.png` - Vercel deploy-button new-project page renders the consolidated #47995 form inside the window chrome - `vercel.ts` changes are deploy-config only — verify Flags Explorer + function timeout on a preview deploy <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added timezone-aware timestamp handling across Studio. - Added support for global keyboard shortcuts. - Updated authentication page layouts for a more consistent sign-in experience. - Refreshed social sharing imagery. - **Bug Fixes** - Improved error reporting and responses when loading function source files fails. - Improved handling of integration page layouts. - Fixed Vercel routing for feature configuration requests. - **Performance** - Added caching for static images and favicons. - Increased server execution time for longer-running requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
4fa3169e8e |
test(logs): regression coverage for datepicker Invalid time value crash (#48027)
## Problem The database-report chart to logs flow could crash the logs date picker with "RangeError: Invalid time value" (react-day-picker formatting an Invalid Date), and there was no regression coverage for it. ## Fix Adds two Vitest tests that reproduce the crash path: - Logs.Datepickers.test.tsx: opening LogsDatePicker with an unparseable value (the legacy epoch-ms its/ite) must render the calendar instead of throwing. - LogsPreviewer.test.tsx (MSW): its/ite from the URL load into the picker and it opens without crashing, covering the chart-to-logs navigation end to end. Note: these tests depend on the fix in #48009. On master the crash-guard test fails with the exact "Invalid time value" error (that is the regression it catches), so CI here will be red until #48009 merges. ## How to test - Run: pnpm --filter studio exec vitest --run tests/features/logs/Logs.Datepickers.test.tsx tests/features/logs/LogsPreviewer.test.tsx - On master: the "unparseable date value" test fails with RangeError: Invalid time value. - With #48009 merged in: both pass. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added coverage to ensure the logs date picker handles legacy or unparseable date values without crashing. * Added coverage verifying log preview date ranges are populated from URL parameters and can be opened successfully. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
18b273cde0 |
fix(studio): hide Postgres Version Upgrade logs behind a flag (#48007)
## Problem The legacy Logs Explorer's Postgres Version Upgrade page (Database Operations section) shows no results for most users. pg_upgrade_logs rows aren't tagged with the project attribute the shared logs endpoint scopes on, only a host field, so the project-scoped query returns nothing even though the data exists. ## Fix Hides the Database Operations sidebar section behind a new showPostgresUpgradeLogs feature flag (default off), following the same pattern as showMultigresLogs. The page route itself is untouched, only the sidebar entry point is gated. ## How to test - With the flag off, open the legacy Logs Explorer sidebar and confirm the Database Operations section and Postgres Version Upgrade item are gone - With the flag on, confirm the section and item render as before <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added conditional access to Postgres Version Upgrade logs based on feature availability. * Failed Postgres upgrade notifications now show a “View logs” option only when supported. * **Bug Fixes** * Prevented unsupported Postgres upgrade log links and navigation options from appearing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6e0078182b |
Consolidate project creation UI for vercel integration flow (#47995)
## Context There's 2 areas of the dashboard that has the project creation flow - and this PR consolidates both to use the same UI components to minimise duplication + keep things consistent ### Before <img width="1920" height="957" alt="image" src="https://github.com/user-attachments/assets/2a7ab79d-71c7-43f2-925b-1e1666cc3a69" /> ### After <img width="1389" height="957" alt="image" src="https://github.com/user-attachments/assets/f8465568-af99-46eb-80ee-7ac345383231" /> ## Changes involved - What this means for the project creation flow for Vercel Integration: - Smart region can be selected - Compute size can be selected - Enable Data API can be checked - Automatic RLS enable can be checked - How it differs from the main project creation flow on `new/slug` - Organization selection is disabled (cannot be changed) - The following UI is hidden: - "Internal configuration" section - "GitHub repository" field - "Free project info" at the bottom - "Cancel" button Eventually we could looking into reducing the differences more, e.g having data seeding for both ways, and showing GitHub repository field for Vercel integration Resolves DEPR-616 Resolves FE-3905 ## To test Tbh, I'm not really sure how you'd be able to test the vercel integration locally or on staging, this seemingly can only be done when changes land on prod. - What I'd do however is to just test the project creation flow minimally by landing on `/integrations/vercel/_/deploy-button/new-project` - Project creation can work, but just not the connection creation part - And also test project creation on `/new/slug` as well <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added “Create sample tables with seed data” during project creation. * Enhanced Vercel integration setup with a guided creation flow and post-creation connection step. * Added an option to disable organization selection in specialized flows. * Added support for triggering a callback after successful project creation. * Added support for hiding the Cancel button in specialized flows. * **UI Improvements** * Refined the connected GitHub repository selector button/dropdown visuals. * Improved security options behavior for different project creation contexts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
beb6d0135a |
fix(studio): mirror Vercel interstitial layout change into TanStack routes (#48024)
## Linked Issue Closes #6362 ## Description The failure fallback in four reranker providers (Cohere, HuggingFace, SentenceTransformer, ZeroEntropy) was writing `rerank_score = 0.0` directly onto the input dicts, while every success path copies before attaching the score (LLMReranker even copies on its per-document failure path). Since `Memory.search()` hands its live result list to `rerank()` (`mem0/memory/main.py:1458`, async twin near line 3096), one transient provider failure permanently stamped the caller's memory dicts from a call that looked successful. This copies each dict in the fallback loop before setting the sentinel, matching the success-path contract. Fallback behavior is otherwise untouched: original order, 0.0 sentinel, config `top_k` slice. The new test file is parametrized over all four providers and proves the regression both ways: all 12 cases fail on main and pass with the fix. Providers are constructed via `object.__new__` with stubbed attributes so the tests run without the optional heavy deps (cohere, transformers, sentence-transformers, zeroentropy) installed. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Refactor (no functional changes) - [ ] Documentation update ## Breaking Changes N/A ## Test Coverage - [x] I added/updated unit tests - [ ] I added/updated integration tests - [x] I tested manually (describe below) - [ ] No tests needed (explain why) Ran `make lint` (clean) and `make test-py-3.11` (1687 passed; the two Redis e2e failures are pre-existing on main and only trigger because a local Redis happens to be reachable on my machine, they are skipped in CI). Also verified the new tests fail without the provider changes. ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have added tests that prove my fix/feature works - [x] New and existing tests pass locally - [x] I have updated documentation if needed --- quick note: I'm a college freshman trying my best to contribute for the greater good :) this fix came out of a session with Claude Code (it did the heavy lifting, I read through the diff and ran the gates locally), so apologies in advance if anything looks off. if there are mistakes I would genuinely love to learn from them. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved the Vercel integration page layout by applying the integration window consistently to the new-project deployment flow. * Prevented duplicate or incorrect layout wrapping on other Vercel integration pages. * Preserved dedicated interstitial layouts for installation and project-selection screens. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: ayaangazali <ayaan.gazly@gmail.com> |
||
|
|
1c827c5cbb |
refactor(sql-editor): extract title-gen/execute-params + merge auto-limit functions (#48013)
## Summary Part 2/6 of the SQL Editor testability follow-up, stacked on #47980 (the analyzeQueryIssues/resolveConnectionString PR). - Extracts `shouldAutoGenerateTitle` and `buildExecuteParams` out of `useSqlEditorExecution`'s inline logic into `SQLEditor.utils.ts`. - Merges `checkIfAppendLimitRequired` and `suffixWithLimit` into a single `applyAutoLimit` function — the two were only ever called together and re-parsed the same query twice at every call site. `applyAutoLimit` only accepts `SafeSqlFragment` (never a plain string) and composes the `LIMIT` suffix through `safeSql`/`literal` rather than raw template concatenation, so the only place in the file that reasserts the `SafeSqlFragment` brand on a derived string is the small, dedicated `trimTrailingSemicolons` helper — removing existing terminators can't introduce unsafe content, unlike gluing new text onto the fragment. - Updates the two other `checkIfAppendLimitRequired`/`suffixWithLimit` call sites (`EditorPanel.tsx`, `ReportBlock.tsx`) accordingly; `ReportBlock` now promotes its report SQL once and reuses the result for both its display-only auto-limit hint and its execution, instead of promoting twice. ## Test plan - [x] `pnpm --filter studio typecheck` - [x] `pnpm test:studio -- SQLEditor ReportBlock EditorPanel` (239 tests passing) |
||
|
|
11fb715149 |
refactor(sql-editor): extract query-issue analysis + connection string resolution (#47980)
## Summary Part 1/6 of the SQL Editor testability follow-up (extracting pure decision logic out of the SQL editor hooks so it can be exhaustively unit-tested without mocking). - Extracts `analyzeQueryIssues` and `hasBlockingIssues` out of `useSqlEditorExecution`'s inline destructive-query / warning-modal-gating logic into `SQLEditor.utils.ts`. - Extracts `resolveConnectionString`, deduping the `databases?.find(...)` lookup that was duplicated verbatim in both `useSqlEditorExecution` and `useSqlEditorExplain`. - Behavior-preserving — same runtime logic, now unit-testable in isolation. ## Test plan - [x] `pnpm --filter studio typecheck` - [x] `pnpm test:studio -- SQLEditor.utils` (159 tests passing, includes new exhaustive-permutation cases for the three extracted functions) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL safety checks before execution, including destructive queries, unsafe updates, database-altering commands, and tables missing row-level security. * Correctly recognizes tables protected by active security triggers. * Improved database connection selection for primary and read-replica databases. * Preserved the ability to run queries with force enabled when safety warnings are present. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9069e8d21e |
fix(reports): chart click selects bucket range, fix logs datepicker crash (#48009)
## Problem In a database report, dragging over a chart to open logs had two bugs. Clicking a bar instead of dragging produced a zero-width selection (its === ite), so the logs view showed no results. Separately, the logs datepicker crashed with "Invalid time value" because the chart put raw epoch-ms values into the its/ite URL params, which get parsed with new Date(string) and yield an Invalid Date that react-day-picker cannot format. ## Fix The chart now emits ISO timestamps in the logs URL so its/ite match the format every other logs consumer already uses, and the datepicker guards against unparseable values from any source (such as old bookmarked links). A single click now expands the highlight to the clicked bucket, from the bar's start to the next bar's start, so the selection, popover, and logs range all cover the bar the user picked. ## How to test 1. Open a database report with a chart (for example Postgres, project logs). 2. Drag across the chart, choose "Open in Postgres Logs", then open the timepicker. Expected: it opens without crashing and shows the selected range. 3. Go back and single-click one bar instead of dragging. Expected: that bar's bucket is selected and "Open in Postgres Logs" loads logs for a real, non-empty range. 4. Run the chart tests, expected all pass: pnpm --filter studio exec vitest --run components/ui/Charts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Prevented invalid log date inputs from creating invalid date selections. * Improved chart “open logs” links by normalizing the selected time bounds (now consistently sent as ISO timestamps). * Refined chart highlight behavior for click-to-advance and more accurate left/right range selection, supporting both numeric and string coordinate values. * Updated the chart highlight dropdown display for clearer formatting of numeric vs non-numeric dates. * **Tests** * Added Vitest coverage for chart highlight click, drag, and left/right ordering scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
58621818d0 |
feat(studio): switch TanStack skew protection to ?dpl= query params (#48008)
Switches the TanStack build's Vercel skew protection from the `__vdpl` session cookie to `?dpl=<deployment-id>` query params baked into asset URLs at build time. Assets stay pinned to the deployment that built them, while document navigations and API fetches always reach the latest deployment (with the cookie, a session stayed fully pinned — including reloads — until the tab closed). **Removed:** - `pinDeploymentForSession` (the `__vdpl` cookie) from `router.tsx`, plus the cookie clearing in the refresh toast and the `vite:preloadError` backstop - `credentials: 'omit'` on the deployment-commit check — its only purpose was escaping the cookie pin, and API fetches are now inherently unpinned **Added:** - `skewProtectionDpl` plugin + `experimental.renderBuiltUrl` in `vite.config.ts`, active only when `VERCEL_SKEW_PROTECTION_ENABLED=1`. Full coverage needs three mechanisms (Vite has no single hook for this — see [vitejs/vite#13834](https://github.com/vitejs/vite/discussions/13834#discussioncomment-7469745)): 1. `renderBuiltUrl` — CSS `url()`s, images, workers, and `__vite__mapDeps` preload lists 2. a `generateBundle` (`order: 'post'`) rewrite of chunk-to-chunk `import`/`from` specifiers, which Rolldown emits as bare relative paths that `renderBuiltUrl` never sees — with sourcemaps recombined per chunk (`magic-string` + `@jridgewell/remapping` devDeps) so Sentry columns stay exact 3. a post-`buildApp` patch of the prerendered `_shell.html` (script/preload tags + embedded router manifest come from TanStack, not Vite's asset pipeline); without it the entry graph double-downloads because preload and import URLs differ ## To test - Built with fake `VERCEL_SKEW_PROTECTION_ENABLED=1 VERCEL_DEPLOYMENT_ID=dpl_TESTPIN123abc`: every chunk import specifier (static + dynamic), `__vite__mapDeps` entry, CSS font URL, and `_shell.html` asset URL carries `?dpl=`; zero unpinned `/assets/` references remain - Sourcemap accuracy verified by tracing a minified position through the recombined map: resolves to the exact original file/line/column (`use-check-latest-deploy.tsx:62:8`) - Built without the env vars: output contains no `dpl=` anywhere (self-hosted/e2e builds unaffected) - `smoke:tanstack` passes on both builds; `tsc --noEmit` and eslint clean - On the preview: load the dashboard, check Network tab — chunk/CSS requests should carry `?dpl=` matching the deployment; hard reload should hit the latest deployment (no pin on document requests) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Improved deployment consistency by pinning generated asset and module URLs to the current deployment (using `?dpl=`). * Simplified refresh and preload-error recovery to reduce reload-loop risk. * Kept API request behavior aligned with the updated deployment routing/pinning approach. * Preserved correct routing across deployment configurations. * **Developer Experience** * Added build-time tooling to rewrite pinned URLs for client assets while maintaining source map integrity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
0bcd2e196d |
fix: invalidate free project limit checks for all organizations when a project is deleted (#47569)
How to test: 1. Have multiple free orgs 2. Open the "create new project" page in those orgs (no need to create a project), notice the `/members/reached-free-project-limit'` API call 3. Delete any project in any of the orgs you have 4. Go to any of orgs and open the "create new project" page, the request should be sent again (it was purged from the cache) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved project deletion behavior so free project limit checks are refreshed across all organizations, reducing the chance of stale availability data. * Continued to refresh the deleted project’s details and, when applicable, the project list and organization details after deletion. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
da74f52421 |
chore(www): Unified Logs open beta blog post (#47645)
Draft blog post announcing Unified Logs in open beta. Post: `apps/www/_blog/2026-07-06-unified-logs-open-beta.mdx` ### Before publishing - [ ] Confirm publish date <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Announced the open beta of Unified Logs, including a single unified, searchable log stream across multiple services. * Introduced log-type filtering with counts, shareable filter/search links, live tailing, and a zoomable timeline for log-volume exploration. * Added per-request details showing request progression and an option to view raw JSON, plus support for forwarding logs externally via Log Drains. * **Content Updates** * Added a new author profile entry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Shane <o@shaneermitano.com> Co-authored-by: Ana <30495040+ana1337x@users.noreply.github.com> |
||
|
|
f29db88edd |
add aria label in Query Performance (#47678)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Changes to the structure of the <Switch> and <Dialog> elements, which previously resulted in two nested buttons in the DOM. Adding the asChild attribute broke the styling of the <Switch>. Added aria-label and tooltips to the <Switch> component and the icon-only buttons. <img width="1909" height="1254" alt="fix_observabilty" src="https://github.com/user-attachments/assets/4dc99845-c083-455b-beed-1ac58b66dd6f" /> ## What is the current behavior? Icon-only buttond do not have explicit accessible names for screen readers. Two nested buttons are invalid in HTML and interfere with the operation of screen readers. ## What is the new behavior? Iicon-only buttons now have explicit accessible names using visually hidden text (sr-only), ensuring proper screen reader support. The DOM structure is now correct. ## Additional context No visual changes were introduced. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Improved accessibility in the query performance filter bar by adding clear `aria-label` values to the Refresh and Reset report buttons. * Improved accessibility and usability for cron job table actions by adding a job-specific “actions” tooltip/label for the dropdown trigger. * Updated the cron job enable/disable toggle with job-specific `aria-label`s and refined the confirmation dialog flow to prevent unintended row interactions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
05d8dd356c | fix: selfhost edge URLs (#47861) | ||
|
|
dac5756295 |
docs(auth): add server-side package disambiguation guide (#47966)
Adds a docs guide, "Choosing a server-side package", that explains when to use `supabase-js`, `@supabase/ssr`, or `@supabase/server` when working with Supabase from JavaScript on the server. It includes a decision table and a short code example for each, with one rule up front: cookie-based sessions in SSR frameworks use `@supabase/ssr`, per-request header auth in Edge Functions and other backend runtimes uses `@supabase/server`, and `supabase-js` is the base client both wrap. The guide is surfaced from the Auth overview page and the sidebar, and is cross-linked from the `supabase-js` and `@supabase/server` reference introductions so it is reachable from where developers start. It also states that the packages coexist and are not replacements for each other, and keeps combining `@supabase/server` with `@supabase/ssr` as an advanced section. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a guide explaining how to choose between Supabase server-side JavaScript packages. - Added the guide to Auth navigation and the getting-started content listings. - Added links to the new guidance throughout relevant JavaScript and server documentation. - **Documentation** - Clarified when to use cookie-based sessions versus header-based authentication. - Added package comparisons, usage examples, advanced guidance, and related next steps. - Updated spelling support for framework names used in the documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
a72a58eeae | feat: Add federated content script. Resolve graphql routes. (#47934) | ||
|
|
8d50a13d33 | docs: note Apple Services ID must be first in Client IDs for web sign-in (#47707) | ||
|
|
04a11b715a |
Fix some colors (#47996)
## Context In the table editor when hovering over a row that has fixed columns, the wordings could appear like they're overlapping <img width="339" height="95" alt="image" src="https://github.com/user-attachments/assets/9de8252c-08fc-4dec-a2f2-21461e47691e" /> This is due to the `bg-surface-200` class that gets applied to rows on hover which use alpha values, hence why it's happening. Opting to use `bg-200` instead which doesn't have alpha values. Also small fix for the copy button in `CodeBlock` as well which is running into the same issue - opting to use a set of colors that doesn't have alpha values instead. <img width="127" height="115" alt="image" src="https://github.com/user-attachments/assets/4d773474-49e0-4c3b-bea1-042ff3102f9c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated table header, row hover, and selected-row background colors for a more consistent appearance. * Enhanced the code block copy button’s dark-mode and hover background styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
591b621567 |
fix(studio): tighten time bounds on single-log inspection query (#47978)
## Summary - The unified log inspection point-lookup (`getUnifiedLogInspection` in `apps/studio/data/logs/unified-log-inspection-query.ts`, used by `ServiceFlowPanel` when a user selects a row to view its detail panel) previously reused the whole selected search date range for its `iso_timestamp_start`/`iso_timestamp_end` bounds, even though it looks up exactly one row by `id`. With a wide search range selected (days/weeks), this scans far more of the ClickHouse-backed `logs` table than necessary. - Since the selected row's own timestamp is already known client-side, the query now bounds itself to a ±1 hour window around that timestamp instead, falling back to the previous search-range behavior when no timestamp is available. - No SQL text changes for the time bound — the `iso_timestamp_start`/`iso_timestamp_end` params are the existing mechanism by which every other query in this file (and sibling logs queries) bounds time server-side, so this follows that same convention rather than adding a redundant inline `WHERE timestamp` clause. - Also added an explicit `AND source = '...'` filter to the OTEL point-lookup SQL. The logs table's primary key is `(project, source, timestamp)`, so filtering on `source` narrows the sorted range before the timestamp bound even applies — the service flow `type` already maps 1:1 to a `source` value, so no new data was needed at the call site. ## Test plan - [ ] Typecheck (couldn't run locally in this environment — no `node_modules` installed) - [ ] Manually verify in Studio: open Logs Explorer with a wide time range (e.g. 7 days), select a log row, confirm the detail/service-flow panel still loads the correct enriched data - [ ] Confirm behavior is unchanged when `logTimestampMs` is unavailable (falls back to search range) 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved unified log inspection accuracy by narrowing the inspection window to ±1 minute around the selected log event when a timestamp is available. * Updated service-flow and OTEL inspection lookups to use the selected log entry’s timestamp for tighter, more relevant results. * Preserved the prior broader time-range behavior when a timestamp isn’t available. * **Refactor** * Centralized log type → source mapping and generated the corresponding query filters from that shared mapping for consistency. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
21418b72ab | Merge branch 'docs/clarify-default-privileges' | ||
|
|
4c31f84c75 |
Apply suggestion from @czenko
Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
22b3419a28 |
Extract project creation form into its own component (#47957)
## Context This is just a pre-requisite to consolidating the project creation UI as there's another page that has the project creation flow too [here](https://github.com/supabase/supabase/blob/master/apps/studio/pages/integrations/vercel/%5Bslug%5D/deploy-button/new-project.tsx). So the next step will just be to use the same `ProjectCreationForm` there No functional changes here - just moving things around ## To test - [ ] Verify that project creation still works <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a full “create project” experience with eligibility-aware defaults, advanced configuration sections, optional GitHub integration, and compute-cost confirmation when applicable. * **Improvements** * Enhanced project-creation success/error handling and navigation. * Refined CLI backup/restore dialogs (better layout/wording, accessibility updates, and improved section separation). * **Documentation** * Standardized all relevant documentation links across the app using a shared `DOCS_URL` source. * **Refactor** * Refactored the “New Project” page to delegate the wizard UI and flow to a reusable creation component. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ae957414b4 |
fix(studio): make unified logs sidebar banner dismissible (#47977)
## Summary - Adds a close button to the "Introducing unified logs" sidebar banner, storing the dismissal in localStorage so it stays hidden. ## Test plan - [ ] Open Logs Explorer, confirm the X dismisses the banner and it stays gone after reload. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an `X` close button to the unified logs preview banner. * Remember banner dismissal using local storage, so it stays hidden after closing. * Updated banner visibility rules to account for unified-logs preview enablement and default opt-in state. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
b100272376 |
chore(sql-editor): remove Pretty Explain feature (#47981)
Removes the SQL Editor Pretty Explain feature — the Explain tab, the Run EXPLAIN ANALYZE action + shortcut, and its dead plumbing. It's been gated off behind the `DisablePrettyExplainOnSqlEditor` kill switch for weeks with no usage or complaints. `ExplainVisualizer` / `isExplainQuery` are kept — they're used independently by Query Insights, Query Performance, and the EditorPanel quick-runner. Manually-run `EXPLAIN` queries still render as raw rows in the Results tab. Typecheck, lint, and all affected unit tests pass. Closes FE-3930 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Changes** * Removed the SQL editor’s EXPLAIN execution workflow, including its toolbar action, keyboard shortcut, utility tab, and visual query-plan display. * Simplified query execution to focus on standard results and charts. * Improved result clearing when switching databases and refined execution error handling. * Updated SQL editor state and tests to reflect the streamlined experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9669e5ea17 |
adding joey to the humans.txt (#47983)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updates Joey Lei to the list of Supabase team members ## What is the current behavior? Missing joey! ## What is the new behavior? Adds Joey ## Additional context None <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Joey Lei to the team credits listed in the documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
963182f58e |
fix: add hasLightIcon field to ContentListings; revert getting-started-overview to GlassPanel (#47467)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix + partial revert. ## What is the current behavior? 1. `ContentListings.client.tsx` unconditionally derives `hasLightIcon` from `Boolean(item.icon)`. `GlassPanel` appends `-light.svg` to the icon path in light mode whenever `hasLightIcon` is true. Framework icons (react, nuxt, hono, redwood, flutter, swift, kotlin, svelte, solidjs, vue, refine, angular, ionic) have no `-light.svg` variants, causing broken image requests in light mode for any ContentListings card that uses them. 2. `getting-started.mdx` uses `<ContentListings id="getting-started-overview" />` (added in #47097) for the top three-card grid (Build with AI tools, API Keys, Local Development). ## What is the new behavior? 1. `hasLightIcon` is now an optional field in the item schema (defaults to `Boolean(item.icon)` for backward compatibility). The component reads `item.hasLightIcon ?? Boolean(item.icon)`, so data files can opt specific icons out of the light-mode variant. 2. `<ContentListings id="getting-started-overview" />` is removed and the original hand-authored GlassPanel grid is restored. The `gettingStartedGetStarted` data entry and its registry import are also removed. ContentListings has no mandate to cover every section of every page: the goal was for hub and overview pages to have a reasonable, standardized link section that tooling can lint for. This page doesn't fit that pattern. ## Additional context | Check | Result | |-------|--------| | `pnpm vitest run lib/content-listings.test.ts` | ✅ 12/12 passed | | `pnpm lint:mdx` (getting-started.mdx) | ✅ No warnings | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the Getting Started guide with dedicated tiles for Build with AI Tools, API Keys, and Local Development. * Expanded the available Getting Started content listings. * **Bug Fixes** * Improved icon styling in content listings so light icon treatment reflects each item’s configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
129d3ccfd5 |
chore(deps): bump pnpm/action-setup from 4.2.0 to 6.0.9 (#47928)
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4.2.0 to 6.0.9. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pnpm/action-setup/releases">pnpm/action-setup's releases</a>.</em></p> <blockquote> <h2>v6.0.9</h2> <h2>What's Changed</h2> <ul> <li>fix: update pnpm to v11.7.0 by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/267">pnpm/action-setup#267</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v6...v6.0.9">https://github.com/pnpm/action-setup/compare/v6...v6.0.9</a></p> <h2>v6.0.8</h2> <h2>What's Changed</h2> <ul> <li>docs(README): fix <code>cache_dependency_path</code> type by <a href="https://github.com/haines"><code>@haines</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/257">pnpm/action-setup#257</a></li> <li>fix: drop patchPnpmEnv so standalone+self-update works on Windows by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/258">pnpm/action-setup#258</a></li> <li>fix: update pnpm to 11.1.1 by <a href="https://github.com/mungodewar"><code>@mungodewar</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/248">pnpm/action-setup#248</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/mungodewar"><code>@mungodewar</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/248">pnpm/action-setup#248</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8">https://github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8</a></p> <h2>v6.0.7</h2> <h2>What's Changed</h2> <ul> <li>fix: honor devEngines.packageManager.onFail=error (<a href="https://redirect.github.com/pnpm/action-setup/issues/252">#252</a>) by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/254">pnpm/action-setup#254</a></li> <li>fix: restore inputs from state in post by <a href="https://github.com/haines"><code>@haines</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/255">pnpm/action-setup#255</a></li> <li>fix: self-update bootstrap to packageManager-pinned version (<a href="https://redirect.github.com/pnpm/action-setup/issues/233">#233</a>) by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/256">pnpm/action-setup#256</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/haines"><code>@haines</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/255">pnpm/action-setup#255</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7">https://github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7</a></p> <h2>v6.0.6</h2> <h2>What's Changed</h2> <ul> <li>fix: bin_dest output points to self-updated pnpm, not bootstrap by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/249">pnpm/action-setup#249</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6">https://github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6</a></p> <h2>v6.0.5</h2> <h2>What's Changed</h2> <ul> <li>fix: append (not prepend) action node dir to PATH for npm bootstrap by <a href="https://github.com/zkochan"><code>@zkochan</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/241">pnpm/action-setup#241</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v6.0.4...v6.0.5">https://github.com/pnpm/action-setup/compare/v6.0.4...v6.0.5</a></p> <h2>v6.0.4</h2> <h2>What's Changed</h2> <ul> <li>fix: use npm co-located with the action node binary by <a href="https://github.com/benquarmby"><code>@benquarmby</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/239">pnpm/action-setup#239</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/benquarmby"><code>@benquarmby</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/239">pnpm/action-setup#239</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pnpm/action-setup/commit/0ebf47130e4866e96fce0953f49152a61190b271"><code>0ebf471</code></a> fix: update pnpm to v11.7.0 (<a href="https://redirect.github.com/pnpm/action-setup/issues/267">#267</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/0e279bb959325dab635dd2c09392533439d90093"><code>0e279bb</code></a> fix: update pnpm to 11.1.1 (<a href="https://redirect.github.com/pnpm/action-setup/issues/248">#248</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/3e835812ef01165f4f8ae08ade56da44427ed4e0"><code>3e83581</code></a> fix: drop patchPnpmEnv so standalone+self-update works on Windows (<a href="https://redirect.github.com/pnpm/action-setup/issues/258">#258</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/551b42e879e37e74d986effdd2a1647d2b02d464"><code>551b42e</code></a> docs(README): fix <code>cache_dependency_path</code> type (<a href="https://redirect.github.com/pnpm/action-setup/issues/257">#257</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/739bfe42ca9233c5e6aca07c1a25a9d34aca49b0"><code>739bfe4</code></a> fix: self-update bootstrap to packageManager-pinned version (<a href="https://redirect.github.com/pnpm/action-setup/issues/233">#233</a>) (<a href="https://redirect.github.com/pnpm/action-setup/issues/256">#256</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/f61705d907761b3b5209e83910fafd1fea50c5a1"><code>f61705d</code></a> chore: add CODEOWNERS</li> <li><a href="https://github.com/pnpm/action-setup/commit/7a5507b117647ab83e96e9db317ba2234056ebf3"><code>7a5507b</code></a> fix: restore inputs from state in post (<a href="https://redirect.github.com/pnpm/action-setup/issues/255">#255</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/1155470f3e5fb872accd4d104b8dfcda41f676ce"><code>1155470</code></a> fix: honor devEngines.packageManager.onFail=error (<a href="https://redirect.github.com/pnpm/action-setup/issues/252">#252</a>) (<a href="https://redirect.github.com/pnpm/action-setup/issues/254">#254</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/91ab88e2619ed1f46221f0ba42d1492c02baf788"><code>91ab88e</code></a> fix: bin_dest output points to self-updated pnpm, not bootstrap (<a href="https://redirect.github.com/pnpm/action-setup/issues/249">#249</a>)</li> <li><a href="https://github.com/pnpm/action-setup/commit/e578e19d19d31b011b841ba2aca34731a5f706a5"><code>e578e19</code></a> fix: update pnpm to 11.0.4</li> <li>Additional commits viewable in <a href="https://github.com/pnpm/action-setup/compare/41ff72655975bd51cab0327fa583b6e92b6d3061...0ebf47130e4866e96fce0953f49152a61190b271">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |