mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 19:05:06 +03:00
fix/docs-e2e-vercel-wait-commit-status
419
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2428bddcb5 |
chore: Bump vulnerable deps (#48178)
Fixes the following vulnerabilities: - https://github.com/supabase/supabase/security/dependabot/3963 - https://github.com/supabase/supabase/security/dependabot/3963 - https://github.com/supabase/supabase/security/dependabot/3964 - https://github.com/supabase/supabase/security/dependabot/3965 - https://github.com/supabase/supabase/security/dependabot/3966 - https://github.com/supabase/supabase/security/dependabot/3927 - https://github.com/supabase/supabase/security/dependabot/3955 - https://github.com/supabase/supabase/security/dependabot/3913 - https://github.com/supabase/supabase/security/dependabot/3972 - https://github.com/supabase/supabase/security/dependabot/3959 - https://github.com/supabase/supabase/security/dependabot/3960 - https://github.com/supabase/supabase/security/dependabot/3916 - https://github.com/supabase/supabase/security/dependabot/3918 - https://github.com/supabase/supabase/security/dependabot/3947 - https://github.com/supabase/supabase/security/dependabot/3948 - https://github.com/supabase/supabase/security/dependabot/3956 - https://github.com/supabase/supabase/security/dependabot/3957 - https://github.com/supabase/supabase/security/dependabot/3958 - https://github.com/supabase/supabase/security/dependabot/3917 - https://github.com/supabase/supabase/security/dependabot/3919 - https://github.com/supabase/supabase/security/dependabot/3970 - https://github.com/supabase/supabase/security/dependabot/3928 - https://github.com/supabase/supabase/security/dependabot/3949 - https://github.com/supabase/supabase/security/dependabot/3950 - https://github.com/supabase/supabase/security/dependabot/3973 - https://github.com/supabase/supabase/security/dependabot/3920 - https://github.com/supabase/supabase/security/dependabot/3951 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the bundled `tar` dependency to a newer patch version for consistency and security across the workspace. * Added/adjusted overrides to pin a few transitive dependencies to specific versions. * Normalized workspace configuration formatting and made minor development configuration cleanup (no functional change). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d847c48464 |
feat: update @supabase/*-js libraries to v2.110.8 (#48156)
This PR updates @supabase/*-js libraries to version 2.110.8. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.8 - Updated @supabase/auth-js to 2.110.8 - Updated @supabase/realtime-js to 2.110.8 - Updated @supabase/postgest-js to 2.110.8 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.8 ## 2.110.8 (2026-07-21) ### 🩹 Fixes - **auth:** downgrade aborted/transient fetch failures from console.error to warn ([#2544](https://github.com/supabase/supabase-js/pull/2544)) - **functions:** clean up cross-signal abort listener on invoke() return ([#2487](https://github.com/supabase/supabase-js/pull/2487)) - **functions:** match response Content-Type case-insensitively ([#2515](https://github.com/supabase/supabase-js/pull/2515)) - **storage:** url-encode object key in CDN purge methods ([#2545](https://github.com/supabase/supabase-js/pull/2545)) - **supabase:** skip Node warning in Deno ([#2541](https://github.com/supabase/supabase-js/pull/2541)) ### ❤️ Thank You - Franco Kaddour @FrancoKaddour - Katerina Skroumpelou @mandarini - Pedro Henrique - Vaibhav @7ttp ## v2.110.7 ## 2.110.7 (2026-07-16) ### 🩹 Fixes - **postgrest:** correct self-reference inference ([#2525](https://github.com/supabase/supabase-js/pull/2525)) - **realtime:** trigger set auth on INITIAL_SESSION event ([#2531](https://github.com/supabase/supabase-js/pull/2531)) - **realtime:** update phoenix to fix presence issue ([#2532](https://github.com/supabase/supabase-js/pull/2532)) ### ❤️ Thank You - Eduardo Gurgel - Filipe Cabaço @filipecabaco - Vaibhav @7ttp This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
9199aad57e |
feat(docs) Add scaffolding and CI/CD step for Docs Playwright (#48120)
Closes DOCS-1197 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem We do not have any E2E testing established. ## Solution This PR creates an ultra-lean starting place for Docs Playwright: - A CI/CD step that skips on draft and relies on Preview for testing - One simple broken link check for one page The goal: - Playwright is implemented where we want it, with an architecture we want, with set-up steps we can build from The anti-goal of this PR: - We have meaningful tests running ## CI/CD steps <img width="1191" height="72" alt="Screenshot 2026-07-21 at 10 17 06 AM" src="https://github.com/user-attachments/assets/eeb2454c-d864-4574-a050-ce39bb3f083f" /> 1. Checkout a thin slice of the repo (`apps/docs`, `packages`, `patches`). 2. Wait for the Vercel **docs** preview for that commit SHA. 3. Use that preview URL as `PLAYWRIGHT_BASE_URL`. 4. Install Node deps and Chromium. 5. Run `pnpm run e2e:docs` (`--grep @quickstart`). 6. If anything fails, upload the HTML report + traces. Manual runs skip the Vercel wait and default to `https://supabase.com` (or whatever URL you enter), then run the full suite (`pnpm run e2e`). ## What the test checks Because this PR is scaffolding, it is doing something very basic: 1. Opens `/docs/guides/getting-started/quickstarts/nextjs` only if a connected file was edited in CI/CD step 2. Asserts the page loaded and the H1 is visible. 3. Collects docs-owned `/docs/**` links from `#sb-docs-guide-main-article`. 4. HTTP-checks each link (no full navigation) and soft-fails so every broken link is reported. Config keeps it cheap: Chromium only, 1 worker, 2 CI retries, failure screenshots/traces. ## Docs vs Studio/Dashboard The setup of Docs Playwright differs from Studio. | | Docs E2E | Studio E2E | |---|---|---| | Location |`e2e/docs/` | `e2e/studio/` | | What it tests | One published docs page + its links | Many Studio UI flows (tables, auth, storage, …) | | Where the app runs | Already-deployed **Vercel preview** | Built and started **on the runner** | | Backend needed | None | Local Supabase via Docker | | Path filtering | Native `on.pull_request.paths` (skip whole workflow) | `dorny/paths-filter` after checkout (workflow starts, heavy steps gated) | | Parallelism | 1 worker, no shards | Matrix of frameworks × 2 shards | | Retries | 2 in CI | 5 in CI | | Reports | HTML report on failure | Blob reports per shard → merge → PR comment | | Draft handling | Explicit draft skip | No draft skip today | | Manual broader run | Yes (`workflow_dispatch`) | No | The big conceptual difference: **Studio owns the environment** (build Studio, start Supabase, hit `localhost`). **Docs borrows Vercel’s preview** and only asks “does this page and its docs links work on the deployed site?” ## Docs architecture justification The docs architecture is deliberately lightweight because docs are **static, published content served by Vercel**, not an interactive app with a backend. That single fact justifies every difference: - **Borrow the Vercel preview instead of building on the runner.** The preview is already the exact artifact users will see, and Vercel builds it for free on every PR. Rebuilding docs on the runner would duplicate that work and risk testing something different from what ships. Studio, by contrast, needs a running app plus a local Supabase, so it *has* to own its environment. - **No backend.** Docs pages don't need a database or auth to render, so there's nothing to spin up. This is what keeps the job cheap enough to run per-PR. - **Native `paths` filtering.** Since the job is cheap and self-contained, an all-or-nothing skip at the workflow level is sufficient—no need for `dorny/paths-filter` to gate expensive setup steps mid-run like Studio does. - **Low parallelism and modest retries.** One page and its links is a tiny surface, so 1 worker is plenty and there's no sharding to coordinate. Retries exist only to absorb transient network flakiness against a live URL, hence 2 rather than Studio's 5 (which also cushions a heavier, stateful environment). - **Non-blocking + draft skip + manual dispatch.** As initial scaffolding checking link health on a deployed site, it should inform rather than gate merges, avoid burning minutes on drafts, and still be runnable on demand against production. In short: **Studio owns its environment because it must; docs borrows Vercel's preview because it can.** The scope is intentionally minimal today. ## Testing 1. Break a docs-owned link in the Next.js quickstart. 1. Follow README instructions to set up and run e2e docs test. 1. Confirm the suite fails. 1. Restore the broken link and re-run. 1. Confirm the suite **passes** (`1 passed`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary - **New Features** - Added a GitHub Actions workflow to run Playwright docs end-to-end tests on PRs and via manual dispatch (with optional base URL), including docs-preview waiting and concurrency cancellation. - **Documentation** - Added `e2e/docs` README with setup, how to run the suite (including UI/debug and single-spec), and how base URL selection works. - **Tests** - Added a quickstarts E2E spec that validates the page and soft-checks docs-owned links resolve. - **Chores** - Added shared Playwright configuration/package scripts and an `e2e/docs` `.gitignore` for test outputs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
3d1d34bbc7 |
chore(studio): add valtio and react-hook-form ESLint ratchet rules (#48037)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / tooling — adds new ESLint rules for `valtio` and `react-hook-form`. ## What is the current behavior? Studio uses `valtio` and `react-hook-form` heavily, but neither library's dedicated ESLint plugin was installed, so their common API pitfalls were only caught at runtime. ## What is the new behavior? Adds `eslint-plugin-valtio` and `eslint-plugin-react-hook-form` (6 rules total) as `warn`, wired into the existing lint ratchet (`scripts/ratchet-rules.json` + baselines) so current violations are grandfathered and only new ones fail CI — no existing code is changed. Since `eslint-plugin-react-hook-form@0.3.1` still calls the removed ESLint 8 `context.getScope()`, it is wrapped with `fixupPluginRules` from `@eslint/compat` so its rules run under flat config / ESLint 9. ## Additional context Baselines captured: `valtio/state-snapshot-rule` (1), `valtio/avoid-this-in-proxy` (1), `react-hook-form/no-use-watch` (77), and the three recommended react-hook-form rules (0 each). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Code Quality** * Expanded linting for Valtio state usage, including safer proxy usage and snapshot-related patterns. * Added React Hook Form lint rules to encourage safer form state handling and discourage problematic watch usage. * Updated accessibility lint configuration and improved ESLint reliability by enabling an ESLint 8→9 compatibility shim for affected rules. * **Maintenance** * Updated ESLint rule baselines and ratcheting settings to match newly enabled rules. * Added required ESLint plugins to the Studio linting setup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
24ce0ba5f8 |
chore: migrate repo to pnpm v11 (#48033)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / dependency tooling update. ## What is the current behavior? The repo is pinned to pnpm 10.24.0. Closes https://linear.app/supabase/issue/FE-3673/migrate-the-repo-to-use-pnpm-v11. ## What is the new behavior? The repo is pinned to pnpm 11.13.1, pnpm v11 workspace settings are migrated to `allowBuilds`, and the Studio Dockerfile installs pnpm 11.13.1. ## Additional context Validated with `CI=true mise exec node@22 -- pnpm install --frozen-lockfile`, `mise exec node@22 -- pnpm run typecheck`, and `mise exec node@22 -- pnpm run lint`; full Prettier check still fails on existing generated docs/router files outside this migration. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated tooling requirements (pnpm **11.13.1**, Node **>=22.13**) and aligned container build tooling accordingly. * Adjusted package manager behavior (scoped registry override, update notifications disabled) and workspace build/engine validation settings. * **Maintenance** * Updated `clean` scripts across apps/packages to remove only build/cache artifacts (no longer delete installed dependencies). * Reduced Turbo `clean` task output to **errors-only** for cleaner logs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dc3c8684cc |
chore(deps): upgrade valtio to v2 (#48031)
Audited all proxy()/useSnapshot() usage against the v1→v2 migration guide; no breaking changes apply (no reused proxy() inputs, no promise-valued state, all consumers already client components). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the Valtio dependency to a newer version for improved compatibility. * **Bug Fixes** * Improved AI assistant persistence in IndexedDB so chat sessions reliably save (while keeping only the most recent 20 messages per chat). * Hardened tabs restoration from storage to fall back to fresh defaults when data is missing, invalid, or fails validation. * **Refactor** * Switched multiple studio panels to use fresh initial-state factories for initialization and reset reliability. * Updated advisor state so the derived notification filter count is no longer exposed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b9c8857394 |
fix(studio): TanStack route parity fixes from Next comparison audit (#48028)
Audited every TanStack route (~300 files) against its Next.js pages-router counterpart — layout wrapping, root providers, API routes, and deploy config — and fixed the divergences found. Same bug class as #48024, plus a few setup-level gaps. **Fixed (user-visible):** - `routes/__root.tsx` was missing `TimezoneProvider` + the `TimestampInfoProvider` bridge, so the stored timezone preference was silently ignored app-wide (timestamps always rendered in browser-local time) - `routes/_auth.tsx` wrapped all 10 auth pages in `AuthenticationLayout` (status banners + extra full-screen scroll container); in Next only `/sign-in` has it via getLayout. The parent is now a passthrough and sign-in wraps at the leaf - `routes/project/$ref/integrations.tsx` hardcoded `ProjectIntegrationsLayout`; the Next pages use `ProjectIntegrationsLayoutDispatch`, which switches to the Marketplace layout when that flag is enabled - `GlobalShortcuts` wasn't mounted, so the shortcuts-reference sheet (`?`) and its command-menu entry were unreachable - `routes/join.tsx` added a full-screen wrapper the Next page doesn't have (double `min-h-screen` around `InterstitialLayout`) **Fixed (behavior/config):** - ConfigCat flags lost the `plan` custom attribute, so plan-targeted flags could evaluate differently - `vercel.ts`: `api/server.js` had no `maxDuration` (Next sets up to 300s per route — stripe-sync, AI streaming); added the `/.well-known/vercel/flags` rewrite + JSON content-type (Flags Explorer endpoint previously fell through to the HTML shell); added `img`/`favicon` cache-control headers - `routes/api/v1/.../functions/$slug/body.ts` (bespoke reimplementation) dropped `apiWrapper`'s global catch — errors now get Sentry capture + the same 500 `{ error }` body - Reverted migration drift in `__root.tsx`: tooltip `delayDuration` 0 → Radix default (matching Next), `og:image` back to `supabase-og.png` - lodash → lodash-es for the whole SSR module graph (#48029, merged into this branch): the lodash CJS build's named-export interop yields non-functions under the Vite SSR module runner, which 500'd every page once `GlobalShortcuts` (or anything calling lodash during SSR render) mounted. An `options.ssr`-gated `resolveId` plugin in `vite.config.ts` serves `lodash-es` (same version, real ESM) to app source, workspace packages, and deps alike; client bundles untouched. Note: dev servers need a restart after pulling this (config change) Also corrected two stale route comments claiming the CLI/Stripe login pages inline `APIAuthorizationLayout` (they inline `InterstitialLayout`). **Not changed (audited, intentionally left):** - Redirect-only pages briefly flash `DefaultLayout` chrome under TanStack (normally unreachable — router-level redirects fire first) - Org pages inherit an inert `AppLayout` div via `routes/_app.tsx` (visually a no-op; Next org pages don't have it) - Adapter-level differences: framework 405s instead of Next's `Allow`-header JSON, `bodyParser.sizeLimit` not enforced on two routes, narrower favicon non-prod detection (commented as known) - Known pre-existing dev console error (also on Next master): closing the shortcuts sheet logs a setState-in-render warning — `@tanstack/react-hotkeys@0.10.0` calls `setOptions` in the `useHotkeySequence` render body, notifying `useHotkeyRegistrations` subscribers mid-render. Worth an upstream report/dep bump as a follow-up ## To test Verified on the local TanStack dev server via Playwright (all pass): - Set a timezone in the account dropdown → log timestamps show that timezone's row in the hover tooltip - `?` opens the shortcuts sheet; `⌘K` → "Show all keyboard shortcuts" does too - `/sign-in` still shows banners/window chrome; `/sign-up`, `/sign-in-sso`, `/forgot-password`, `/cli/login` render without the extra wrapper - `/project/<ref>/integrations` renders (legacy sidebar when marketplace flag off) - `/join` renders a single centered interstitial - `og:image` meta is `supabase-og.png` - Vercel deploy-button new-project page renders the consolidated #47995 form inside the window chrome - `vercel.ts` changes are deploy-config only — verify Flags Explorer + function timeout on a preview deploy <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added timezone-aware timestamp handling across Studio. - Added support for global keyboard shortcuts. - Updated authentication page layouts for a more consistent sign-in experience. - Refreshed social sharing imagery. - **Bug Fixes** - Improved error reporting and responses when loading function source files fails. - Improved handling of integration page layouts. - Fixed Vercel routing for feature configuration requests. - **Performance** - Added caching for static images and favicons. - Increased server execution time for longer-running requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
58621818d0 |
feat(studio): switch TanStack skew protection to ?dpl= query params (#48008)
Switches the TanStack build's Vercel skew protection from the `__vdpl` session cookie to `?dpl=<deployment-id>` query params baked into asset URLs at build time. Assets stay pinned to the deployment that built them, while document navigations and API fetches always reach the latest deployment (with the cookie, a session stayed fully pinned — including reloads — until the tab closed). **Removed:** - `pinDeploymentForSession` (the `__vdpl` cookie) from `router.tsx`, plus the cookie clearing in the refresh toast and the `vite:preloadError` backstop - `credentials: 'omit'` on the deployment-commit check — its only purpose was escaping the cookie pin, and API fetches are now inherently unpinned **Added:** - `skewProtectionDpl` plugin + `experimental.renderBuiltUrl` in `vite.config.ts`, active only when `VERCEL_SKEW_PROTECTION_ENABLED=1`. Full coverage needs three mechanisms (Vite has no single hook for this — see [vitejs/vite#13834](https://github.com/vitejs/vite/discussions/13834#discussioncomment-7469745)): 1. `renderBuiltUrl` — CSS `url()`s, images, workers, and `__vite__mapDeps` preload lists 2. a `generateBundle` (`order: 'post'`) rewrite of chunk-to-chunk `import`/`from` specifiers, which Rolldown emits as bare relative paths that `renderBuiltUrl` never sees — with sourcemaps recombined per chunk (`magic-string` + `@jridgewell/remapping` devDeps) so Sentry columns stay exact 3. a post-`buildApp` patch of the prerendered `_shell.html` (script/preload tags + embedded router manifest come from TanStack, not Vite's asset pipeline); without it the entry graph double-downloads because preload and import URLs differ ## To test - Built with fake `VERCEL_SKEW_PROTECTION_ENABLED=1 VERCEL_DEPLOYMENT_ID=dpl_TESTPIN123abc`: every chunk import specifier (static + dynamic), `__vite__mapDeps` entry, CSS font URL, and `_shell.html` asset URL carries `?dpl=`; zero unpinned `/assets/` references remain - Sourcemap accuracy verified by tracing a minified position through the recombined map: resolves to the exact original file/line/column (`use-check-latest-deploy.tsx:62:8`) - Built without the env vars: output contains no `dpl=` anywhere (self-hosted/e2e builds unaffected) - `smoke:tanstack` passes on both builds; `tsc --noEmit` and eslint clean - On the preview: load the dashboard, check Network tab — chunk/CSS requests should carry `?dpl=` matching the deployment; hard reload should hit the latest deployment (no pin on document requests) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Improved deployment consistency by pinning generated asset and module URLs to the current deployment (using `?dpl=`). * Simplified refresh and preload-error recovery to reduce reload-loop risk. * Kept API request behavior aligned with the updated deployment routing/pinning approach. * Preserved correct routing across deployment configurations. * **Developer Experience** * Added build-time tooling to rewrite pinned URLs for client assets while maintaining source map integrity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
360bae3871 |
feat: update @supabase/*-js libraries to v2.110.6 (#47968)
This PR updates @supabase/*-js libraries to version 2.110.6. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.6 - Updated @supabase/auth-js to 2.110.6 - Updated @supabase/realtime-js to 2.110.6 - Updated @supabase/postgest-js to 2.110.6 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.6 ## 2.110.6 (2026-07-15) ### 🩹 Fixes - **postgrest:** type hinted self-referencing embeds as arrays ([#2520](https://github.com/supabase/supabase-js/pull/2520)) - **realtime:** forward opts to send() in track() ([#2490](https://github.com/supabase/supabase-js/pull/2490)) - **supabase:** warn instead of throw for unrecognized sb_ API key subtypes ([#2526](https://github.com/supabase/supabase-js/pull/2526)) ### ❤️ Thank You - Franco Kaddour @FrancoKaddour - Katerina Skroumpelou @mandarini ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](https://github.com/supabase/supabase-js/pull/2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](https://github.com/supabase/supabase-js/pull/2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](https://github.com/supabase/supabase-js/pull/2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique ## v2.110.3 ## 2.110.3 (2026-07-13) ### 🩹 Fixes - **auth:** preserve pkce verifier ([#2513](https://github.com/supabase/supabase-js/pull/2513)) - **postgrest:** pin tstyche target off floating latest ([#2509](https://github.com/supabase/supabase-js/pull/2509)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp ## v2.110.2 ## 2.110.2 (2026-07-09) ### 🩹 Fixes - **auth:** clear local session on signout failures ([#2504](https://github.com/supabase/supabase-js/pull/2504)) ### ❤️ Thank You - Luc Peng This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
d23f86021a |
feat(www): Partner Catalog update (#46757)
## Info architecture change around "Partners" The www "integrations" now become more partner-driven. `/partners/integrations` -> now Partner Catalog under `/partners/catalog` (old links redirect to new paths) Moved them close together in the nav dropdown and in the footer <img width="494" height="336" alt="Screenshot 2026-07-09 at 11 06 41" src="https://github.com/user-attachments/assets/a875fef0-0ab8-47ca-8756-d658b27c4892" /> <img width="1149" height="665" alt="Screenshot 2026-07-09 at 11 09 48" src="https://github.com/user-attachments/assets/9631bb72-fe25-4fb4-b1af-9f14a37d02e7" /> ## /partners This page remains untouched in this PR, updates to layout, content and intake form are delegated to #47874 ## /partners/catalog Listed in the [catalog](https://zone-www-dot-com-git-feat-www-partners-pages-supabase.vercel.app/partners/catalog) are now partners. Some partners match with a listing. <img width="1207" height="866" alt="Screenshot 2026-07-09 at 11 14 17" src="https://github.com/user-attachments/assets/b65216be-976f-4ef5-91f8-1ad49da87b45" /> ## /partners/catalog/[partner] Each partner can have one or more "listings" which are either - simple guides - foreign data wrappers - dashboard integrations Integrations available in the dashboard now all have a prominent "Install integration" cta to open it in the dashboard [integrations page](https://supabase.com/dashboard/project/_/integrations). <img width="1269" height="776" alt="Screenshot 2026-07-09 at 11 16 51" src="https://github.com/user-attachments/assets/3c7bb715-ffce-4d0a-905f-9a660c3b1f5a" /> ## Docs Update docs → [Preview](https://docs-git-feat-www-partners-pages-supabase.vercel.app/docs/guides/integrations) - remove "Supabase marketplace" - use "Dashboard Integrations and Partner Catalog - update integrations in sidenav to link to updated /partners/catalog/** listings <img width="1520" height="696" alt="Screenshot 2026-07-15 at 12 54 47" src="https://github.com/user-attachments/assets/9f5a2794-4536-4299-97df-9732d3d75b4c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Partner Catalog experience with search, category filters, official-partner toggle, responsive filtering (sidebar + bottom sheet), grid/list views, and featured partners. * Added Partner Catalog detail pages with tabbed listings, MDX-rendered content, image gallery with zoom overlay, and “add/install” actions. * **Improvements** * Updated “Become a Partner” layout and form support for prefilled values and checkbox-group fields (including validation). * Updated navigation/footer/docs and partner tile links to use Partner Catalog routes; expanded redirects from legacy integrations paths. * Added public agent-skills discovery manifest. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alan Daniel <stylesshjs@gmail.com> Co-authored-by: Alex Hall <alex.hall@supabase.io> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
fd5ec9fade |
Revert "feat: update @supabase/*-js libraries to v2.110.5" (#47918) (#47945)
Reverts #47918. ## Summary - Reverts `@supabase/auth-js`, `@supabase/postgrest-js`, `@supabase/realtime-js`, `@supabase/supabase-js` from 2.110.5 back to 2.110.1 in `pnpm-workspace.yaml` and `pnpm-lock.yaml`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated Supabase package versions to improve compatibility and consistency across the project. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3ed7c8f522 |
feat: update @supabase/*-js libraries to v2.110.5 (#47918)
This PR updates @supabase/*-js libraries to version 2.110.5. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.5 - Updated @supabase/auth-js to 2.110.5 - Updated @supabase/realtime-js to 2.110.5 - Updated @supabase/postgest-js to 2.110.5 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](https://github.com/supabase/supabase-js/pull/2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](https://github.com/supabase/supabase-js/pull/2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](https://github.com/supabase/supabase-js/pull/2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique ## v2.110.3 ## 2.110.3 (2026-07-13) ### 🩹 Fixes - **auth:** preserve pkce verifier ([#2513](https://github.com/supabase/supabase-js/pull/2513)) - **postgrest:** pin tstyche target off floating latest ([#2509](https://github.com/supabase/supabase-js/pull/2509)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp ## v2.110.2 ## 2.110.2 (2026-07-09) ### 🩹 Fixes - **auth:** clear local session on signout failures ([#2504](https://github.com/supabase/supabase-js/pull/2504)) ### ❤️ Thank You - Luc Peng This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
1d29b4c5b4 |
Clean up RLS Tester artifacts (#47866)
## Context As per PR title - we're pausing the development of the RLS Tester feature preview while we re-evaluate its direction. Have also updated the GH discussion [here](https://github.com/orgs/supabase/discussions/45233) RE this! 🙏 Removes the RLS Tester UI + Sandbox functionality <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Removed Features** * Removed the RLS Tester feature preview, banner, and database policy testing workflow. * The related SQL testing, role selection, policy summaries, sandbox management, and result views are no longer available. * **Bug Fixes** * Improved accessibility on the database policies page by adding a label to the clear-filter button. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d863da8680 |
chore: Bump vulnerable dependencies (#47686)
Bump deps to fix https://github.com/supabase/supabase/security/dependabot/3911. |
||
|
|
ad181489b1 |
feat(studio): adopt @sentry/tanstackstart-react server instrumentation on the TanStack build (#47724)
Stacked on #47666 (base `alaister/tanstack-sentry-init`; retarget to `master` when that merges). **Supersedes #47721** (the manual `@sentry/node` wrapper). Client stays on #47666's `@sentry/react` setup. Adopts the official `@sentry/tanstackstart-react` SDK **on the server only**, after a spike (#47723) evaluating the full unified client+server SDK. The spike found the SDK's **browser** `tanstackRouterBrowserTracingIntegration` is a broken no-op stub at 10.59.0/10.64.0 — so the client stays on `@sentry/react` (whose equivalent integration is a real, working implementation, already shipped in #47666). The **server** exports, however, are a clear upgrade and slot in cleanly. ### What this adds (server-side, TanStack build only) - **`instrument.server.mjs`** — `Sentry.init` from `@sentry/tanstackstart-react`, mirroring `sentry.server.config.ts` + `release: VERCEL_GIT_COMMIT_SHA`. - **`start.ts`** — `sentryGlobalRequestMiddleware` + `sentryGlobalFunctionMiddleware` at the front of the existing `createStart(...)` middleware. **This is the win**: it captures request- and server-function errors *including the ones swallowed into 500s* — the exact class the manual wrapper (and the Next server SDK) miss. - **`api/server.js` / `scripts/serve.js`** — gated (`STUDIO_FRAMEWORK==='tanstack'`) instrument init + `wrapFetchWithSentry` on the handler. - **`vite.config.ts`** — `sentryTanstackStart({ …, autoInstrumentMiddleware: false })` as the last plugin: source-map upload + release injection (skips gracefully without an auth token). Middleware is wired explicitly rather than via the plugin's string-rewrite. ### Guarantees - **Client untouched** — the `@sentry/nextjs`→`@sentry/react` alias and #47666's client init are unchanged. - **Next untouched** — `instrumentation.ts` / `sentry.server.config.ts` etc. stay as-is; all new code is TanStack-gated. - **No server SDK in the client bundle** — verified after build: no `@sentry/node` / server middleware / `wrapFetchWithSentry` in `dist/client/assets` (`start.ts`'s server import is tree-shaken out). ### Verified TanStack build exit 0 (past `assertNoChunkCycles`), post-build server boot served `/api/get-utc-time → 200`, `tsc --noEmit` clean, prettier/eslint clean. Node smoke: no-DSN init is a clean no-op; wrapped handler returns 200. ### To test (deploy with a server DSN) Throw a server error from an `/api/*` route (or a `/_serverFn/*`) — including one that gets turned into a 500 without rethrowing — and confirm a server event in Sentry with `release` = the deploy SHA. Compared to #47721, the swallowed-500 case should now be captured via the middleware. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Sentry integration for the Studio app’s TanStack Start runtime, including request and server-function instrumentation. * Wrapped server request handling to capture errors reliably, with tracing enabled. * Updated build tooling to conditionally upload source maps when credentials are present. * **Bug Fixes** * Improved resilience by safely falling back to a no-op Sentry setup if instrumentation cannot be loaded. * Ensured existing request protection remains enabled while adding observability middleware. * **Chores / Config** * Added `SKIP_ASSET_UPLOAD` to the build environment list to control cache/build behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a3f2c4ffc1 |
chore(deps): upgrade to TypeScript 7 (native compiler) (#47757)
Upgrades the monorepo to TypeScript 7.0.2, released 2026-07-08. `tsc` is now the native Go compiler ([announcement](https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/)) — full turbo typecheck drops from ~56s to ~19s locally. TS 7.0 ships **without a programmatic API** (it lands in 7.1), so this uses Microsoft's recommended side-by-side setup: the `typescript` name resolves to `@typescript/typescript6` (the 6.0 API republished) for API consumers — typescript-eslint and Next.js build typechecking — while `@typescript/native` (the real `typescript@7.0.2`) owns the `tsc` bin that typecheck scripts run. Exactly one version of each is in the lockfile; nothing imports the native package as a library. When 7.1 + tool support lands we can collapse back to a single `typescript` dep in the catalog. **Changed:** - `pnpm-workspace.yaml`: catalog aliases for `typescript` / `@typescript/native` - 17 package.json files: `@typescript/native` added beside each `typescript` dep so every package's `tsc` is the native binary - `apps/studio/tsconfig.json`: exclude `dist/` (gitignored build output) from typechecking **Fixed** (real type errors TS 6 under-reported): - `packages/ui-patterns` CodeBlock: `borderLeft: null` → `undefined` (`CSSProperties` doesn't accept null) - `apps/www` CodeBlock: removed a JSX `@ts-ignore` comment that tsgo doesn't honor and fixed what it masked (untyped `.js` theme objects, possibly-undefined highlighter children) ⚠️ **Merge timing:** the new packages are inside pnpm's 3-day `minimumReleaseAge` window until ~July 11. Installs from the committed lockfile are unaffected (resolution is skipped), but anything that forces a re-resolution before then will fail — hold off merging until the window passes. Note for editors: the compat package has no `lib/tsserver.js`, so VS Code's "Use Workspace Version" won't work — use the bundled TS or the TypeScript Native Preview extension. ## To test - `pnpm install && pnpm typecheck` — all 15 tasks green, and `./node_modules/.bin/tsc --version` prints 7.0.2 - `pnpm lint --filter=studio` — typescript-eslint still parses (resolves the 6.0 API) - `pnpm build --filter=design-system` (or any Next app) — Next's tsconfig validation and build typecheck still work - CodeBlock rendering on www (syntax highlighting, line highlights with/without border) — the two fixes are behavior-neutral but worth an eyeball <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements / New Features** * Enhanced TypeScript tooling support across the workspace for smoother development builds and checks. * **Bug Fixes** * Code blocks render more reliably when content is empty or missing. * Highlighted code line styling applies more consistently. * **Maintenance** * Studio TypeScript builds now avoid including generated output (such as `dist`) during compilation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
369744eb2b |
chore: replace concurrently with npm-run-all in docs and design-system (#47697)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / dependency cleanup. ## What is the current behavior? `apps/docs` and `apps/design-system` use the `concurrently` package to run their parallel dev scripts, while the rest of the monorepo (e.g. `packages/pg-meta`) already relies on `npm-run-all`. ## What is the new behavior? Both apps now use `npm-run-all` (`run-p`), and `concurrently` is dropped from their dependencies and the lockfile; `apps/docs` keeps its kill-on-exit behavior via `run-p --race`, and `apps/design-system`'s `dev:full` is collapsed into `dev` using the `run-p dev:*` glob (with `dev:next`/`dev:content` sub-tasks and README updated to match). ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated design system setup instructions to reflect the new development workflow and MDX watching behavior. * **Chores** * Simplified local development scripts for the design system and docs apps. * Split the dev workflow into separate commands for the app server and content watcher, making it easier to run and troubleshoot. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
69121ed8e6 |
feat: update @supabase/*-js libraries to v2.110.1 (#47687)
This PR updates @supabase/*-js libraries to version 2.110.1. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.1 - Updated @supabase/auth-js to 2.110.1 - Updated @supabase/realtime-js to 2.110.1 - Updated @supabase/postgest-js to 2.110.1 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.1 ## 2.110.1 (2026-07-07) ### 🩹 Fixes - **auth:** defer init-time notifications until initializePromise resolves ([#2498](https://github.com/supabase/supabase-js/pull/2498)) - **realtime:** suppress disconnected status from onHeartbeat consumers ([#2496](https://github.com/supabase/supabase-js/pull/2496)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini ## v2.110.0 ## 2.110.0 (2026-06-30) ### 🚀 Features - **repo:** drop Node.js 20 support ([#2482](https://github.com/supabase/supabase-js/pull/2482)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini ## v2.109.0 ## 2.109.0 (2026-06-30) ### 🚀 Features - **auth:** add custom_claims_allowlist to custom providers admin API ([#2473](https://github.com/supabase/supabase-js/pull/2473)) - **realtime:** add postgres_changes filter builder, new operators and select ([#2463](https://github.com/supabase/supabase-js/pull/2463)) - **storage:** expose purgeCache for buckets and single objects ([#2429](https://github.com/supabase/supabase-js/pull/2429)) ### 🩹 Fixes - **functions:** honor a caller's Content-Type override regardless of casing ([#2455](https://github.com/supabase/supabase-js/pull/2455)) - **realtime:** pin @supabase/phoenix and browser test CDN deps ([#2457](https://github.com/supabase/supabase-js/pull/2457)) - **realtime:** add replication connection system message option ([#2470](https://github.com/supabase/supabase-js/pull/2470)) - **storage:** keep sortBy defaults when list() is given a partial sortBy ([#2454](https://github.com/supabase/supabase-js/pull/2454)) ### ❤️ Thank You - Anubhav Anand @i-anubhav-anand - Cemal Kılıç @cemalkilic - Claude Opus 4.8 (1M context) - Filipe Cabaço @filipecabaco - Katerina Skroumpelou @mandarini - Lenny - Rodrigo Mansueli @mansueli This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
4b7cb27ba9 |
chore: refactor docs tabs (#47557)
## Problem Now that `docs` is the only place where we use the deprecated `ui/Tabs`, we can move this component and the related HOC from `ui-patterns` in `docs` ## Solution - Move `ui/Tabs`, `ui-patterns/ComplexTabs/withQueryParams` and `ui-patterns/ComplexTabs/withSticky` to `docs` - Refactor `ui-patterns/ComplexTabs/withQueryParams` and `ui-patterns/ComplexTabs/withSticky` HOCs as hooks to make them easier to understand - Refactor `Tabs` accordingly No visual nor functional changes. ## How to test On https://docs-git-chore-refactor-docs-tabs-supabase.vercel.app/docs/guides/auth/passwords (Tabs are driven by URL and the flow tabs should have sticky headers even though there's a CSS bug already reported) - check that by default, the first tab in each tabs is active - change the tabs in different groups and validate it works - refresh the page and check that previously selected tabs are active (URL based selection) - In a new tab, visit https://docs-git-chore-refactor-docs-tabs-supabase.vercel.app/docs/guides/auth/passwords again and check that previously selected tabs are active (LocalStorage based selection) Do the same on https://docs-git-chore-refactor-docs-tabs-supabase.vercel.app/docs/guides/database/database-advisors (This one is driven by URL but does not have sticky tab headers) Do the same on https://docs-git-chore-refactor-docs-tabs-supabase.vercel.app/docs/guides/deployment/terraform/reference (this one is not driven by URL nor has sticky tab headers) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Docs tabs now persist and restore the active tab via URL query parameters. * Added optional “sticky” tab behavior that keeps the active panel in view. * Enhanced keyboard interaction for selecting tabs. * **Bug Fixes** * Improved active-tab initialization and synchronization when the URL query changes. * **Chores** * Refreshed the tabs UI implementation and styling to improve consistency and remove deprecated tab exports from shared UI packages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74881cbb73 |
feat: render the mcp config component as markdown (#47292)
Renders the MCP config component as markdown for static markdown builds. Currently we have no special case for `<McpConfigPanel />`, so it gets stripped out during markdown rendering. This adds a static markdown version of this component that renders all agents/tools consecutively. Adds a new `McpConfigPanel.md.tsx` component that reuses data structures used by `McpConfigPanel.tsx` but renders as markdown instead of React. Instead of building the markdown via string concatenation, we use [supabase-community/mdast-jsx](https://github.com/supabase-community/mdast-jsx) which allows you to author markdown using JSX (providing type safety, better DX, maintainability). E.g. ```jsx <code lang="json" value='{ "key": "value" }' /> ``` produces: ````md ```json { "key": "value" } ``` ```` ## Preview https://docs-git-feat-mcp-config-markdown-supabase.vercel.app/docs/guides/ai-tools/mcp.md <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Added a docs-only MCP configuration panel with client-specific setup steps, deep links, and generated configuration snippets. - Enhanced guide generation to render richer, component-produced markdown content. - **Bug Fixes** - Improved MCP config serialization and display for consistent JSON/YAML/TOML output. - **Refactor** - Centralized MCP client metadata, instruction content, and config build/serialization logic for reuse. - **Chores** - Expanded package exports for MCP URL builder assets and utilities; improved runtime code-block language validation and updated PNG asset typing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
0e3364bbad |
Chore/cleanup studio deps (#47399)
## Problem Knip reported some unused dependencies. Some are actually used in builds, etc but others are not. ## Solution Remove the really unused dependencies <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Cleaned up unused dependencies and removed some obsolete test/support files. * Updated project ignore rules to better match current app structure and generated files. * **Bug Fixes** * No user-facing behavior changed; this release is focused on maintenance and cleanup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0361d1b727 |
chore: Remove CDN loading for the Monaco editor in all environments (#47182)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Standardized Monaco Editor package versions across the workspace using the shared dependency catalog. * **Bug Fixes** * Improved Monaco initialization by configuring asset loading only on the client and serving Monaco assets from a single base-path URL (removing platform-specific switching). * Streamlined Monaco stylesheet injection in Studio’s document rendering. * **New Features** * Added/updated Monaco language support in Studio, including GraphQL, SQL, and PostgreSQL, with refreshed HTML, JSON, and CSS editor modes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cd62b0b9d4 |
www: product pages (#47271)
Update product pages in marketing website. PR breakdown of #43455 Related: #47226 #47227 #47228 #47236 |
||
|
|
631209f7ce |
chore: Bump vulnerable dependencies (#47269)
Bump several packages: - Bump all instances of dompurify (patch version bump) - Bump `posthog-js` to get a newer version of `@opentelemetry/core` - Bump `@sentry/nextjs` to get a newer version of `@opentelemetry/core` - Bump `redocly-cli` to get a newer version of `@opentelemetry/core` - Bump `undici` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated several project dependencies to newer versions, including documentation tooling, analytics, and error-tracking packages. * These updates may improve stability, compatibility, and access to the latest fixes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9eab4f8fbf |
build(studio): Vite/TanStack-Start build pipeline behind flag (stack 1/6, from #46424) (#47107)
**Stack 1/6** of the TanStack Start migration (#46424), split into reviewable, independently-mergeable PRs. > [!IMPORTANT] > **Next stays the default and only active framework after this PR.** This wires up the Vite/TanStack-Start build pipeline behind the `STUDIO_FRAMEWORK` flag, but there are no TanStack routes yet — so the TanStack build isn't functional or tested until later PRs in the stack. Nothing about the Next build, dev, or deploy changes behaviourally here. ## What's in this PR - **Dispatch:** `dev`/`build`/`start` now go through `scripts/dispatch.js`, which runs the Next variant unless `STUDIO_FRAMEWORK=tanstack`. The original commands are preserved as `dev:next`/`build:next`/`start:next`. - **Build pipeline:** `vite.config.ts`, `serve.js`, `smoke-server.mjs`, vite/tanstack deps, `turbo.jsonc`. - **`tsconfig.json`:** `jsx: react-jsx`, `moduleResolution: Bundler`, `target: ES2022`. Because `include` is `**/*.ts(x)`, this re-typechecks the whole app, so the companion adaptations below land with it. - **Shared adaptations (companions to the tsconfig change):** `BufferSource` casts, `packages/ui` unused-`React` import removals, etc. - **Routing/middleware plumbing:** `next.config.ts` + `redirects.shared.ts` (redirect rules now shared with `vercel.ts`), `proxy.ts`/`start.ts` middleware + `hosted-api-allowlist.ts`. ## Verification Run locally off `master`: frozen install ✓, `studio` typecheck ✓, **Next build ✓** (compiles + generates all routes), lint ratchet ✓ ("some rules improved"), prettier ✓. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a hosted API endpoint allowlist to return 404 for non-supported `/api/*` routes. * Introduced a TanStack route-migration checklist and expanded TanStack Start routing support. * **Improvements** * Enhanced deployment refresh/detection by tightening cookie handling for “latest deployment” updates. * Centralized redirect/maintenance-mode rules for consistent platform vs self-hosted behavior. * Improved production serving with a dedicated static + proxy server and a post-build smoke test. * **Dependencies** * Updated TanStack-related packages and React Table/query tooling versions. * **Documentation / Chores** * Updated formatting and tooling config; added shared build environment parsing utilities. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
96dfc746b7 |
fix: bump stripe sync engine package (#47105)
Bumps the Stripe Sync Engine package to version 1.0.32. Note that the package name has also changed from `stripe-experiment-sync` to `@stripe/sync-engine`. Manual tests run on preview: - [x] Install a fresh version of 1.0.32. - [x] Uninstall freshly installed version 1.0.32 - [x] Upgrade from a lower version (1.0.31 tested) - [x] Upgrade to 1.0.32 and uninstall - [x] Confirm that data is being synced |
||
|
|
91861c4a1f |
feat: allow to filter function by code (#46743)
## Problem It's hard to find a function that references another database entity: users have to open each of them and look for matches themselves. ## Solution Add a search input dedicated to function content filtering. Reusing the existing input to match both names and content may be worse than before as it would match too many functions if some of them have common sql keywords in their name. ## Screenshots <img width="2908" height="672" alt="image" src="https://github.com/user-attachments/assets/38e35512-d733-434e-8b44-6ff043c01c7e" /> <img width="2904" height="560" alt="image" src="https://github.com/user-attachments/assets/36643865-a1c8-4943-8f13-00272e44eea1" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Search now performs fuzzy matching over function names and bodies, ranks exact-name matches higher, and respects schema/return-type/security filters via centralized filtering logic. * **Style / UI** * Search input placeholder updated to "Search for a function by name". * **Documentation / Messaging** * Empty-state messaging clarified to distinguish no functions vs. no search matches. * **Tests** * Added tests covering the new filtering and ranking behavior. * **Chores** * Added runtime dependency for fuzzy-search library. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d46dafc0a |
chore: Bump vulnerable dependencies (#47029)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Chores** * Updated shared development dependencies including build tools and code transformation utilities to latest compatible versions for improved performance and stability across the workspace. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f761c66a9f |
feat: update @supabase/*-js libraries to v2.108.2 (#46927)
This PR updates @supabase/*-js libraries to version 2.108.2. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.108.2 - Updated @supabase/auth-js to 2.108.2 - Updated @supabase/realtime-js to 2.108.2 - Updated @supabase/postgest-js to 2.108.2 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.108.2 ## 2.108.2 (2026-06-15) ### 🩹 Fixes - **auth:** preserve valid session on refresh failure and cooldown repeat failures ([#2436](https://github.com/supabase/supabase-js/pull/2436)) - **realtime:** clarify httpSend() 404 error and server migration note ([#2444](https://github.com/supabase/supabase-js/pull/2444)) - **release:** pin Deno and bound JSR publish to survive stranded-task hangs ([#2439](https://github.com/supabase/supabase-js/pull/2439)) - **release:** restore JSR publish flags and enable for beta ([#2440](https://github.com/supabase/supabase-js/pull/2440)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini ## v2.108.1 ## 2.108.1 (2026-06-09) ### 🩹 Fixes - **ci:** forward DOGFOOD_APP_CLIENT_ID to dogfood workflow ([#2434](https://github.com/supabase/supabase-js/pull/2434)) - **postgrest:** then typing ([#2349](https://github.com/supabase/supabase-js/pull/2349)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
e1ccc31fcc |
chore: Disable some of the Studio features on Multigres projects (#46775)
This PR disables the following features on Multigres projects <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Enhanced replication interface with improved visual states. * **Bug Fixes** * Added validation to prevent incompatible database configuration combinations. * **Changes** * High Availability projects now display informational notices indicating unavailable features: Realtime, Replication, and PITR backups. * **Removed** * Removed redundant UI component from the application. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
4cdbe67980 |
chore: Bump vulnerable dependencies (#46840)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated React Router packages to v7.17.0 for improved routing stability. * Adjusted workspace dependency governance and overrides for more consistent installs. * Removed an obsolete PostCSS re-export. * **New Features** * Integrated Tailwind into the build pipeline to enable utility-first styling. * **Style** * Added global base styles to standardize border color across UI elements. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
10d0b63950 |
feat: update @supabase/*-js libraries to v2.108.0 (#46740)
This PR updates @supabase/*-js libraries to version 2.108.0. **Source**: manual **Changes**: - Updated @supabase/supabase-js to 2.108.0 - Updated @supabase/auth-js to 2.108.0 - Updated @supabase/realtime-js to 2.108.0 - Updated @supabase/postgest-js to 2.108.0 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.108.0 ## 2.108.0 (2026-06-08) ### 🚀 Features - **auth:** auth.resend() consistent confirmation flow ([#2144](https://github.com/supabase/supabase-js/pull/2144)) ### 🩹 Fixes - **auth:** do not console.error AuthApiError already returned through contract ([#2428](https://github.com/supabase/supabase-js/pull/2428)) - **postgrest:** pass request headers as plain object for RN/custom-fetch compatibility ([#2414](https://github.com/supabase/supabase-js/pull/2414)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Lawrence Li @weilirs - MaitreyeeDeshmukh This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
6470ac9186 |
chore(studio): marketplace styling (#46574)
- Marketplace index page - update order of feature partner integrations in hero - fix z-index on MarketplaceFilterBar in "list" view <img width="275" height="104" alt="Screenshot 2026-06-02 at 17 07 29" src="https://github.com/user-attachments/assets/5cef64f9-895e-4f8d-8f30-153ddd5c89dd" /> - Marketplace detail page - use "prose" css styling on overview content for better text styling (heading with top padding, etc) - refine FilesView in overview tab to only show swipeable and zoomable previews (so the big image doesn't occupy too much space) + lazy load FilesView component - improve page loading state - improve overview side rail sticky-top and remove redundant "About" label <img width="1333" height="732" alt="Screenshot 2026-06-02 at 17 20 29" src="https://github.com/user-attachments/assets/8f3dd4a0-c241-4b7f-b8c8-192e1d7a616d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Interactive carousel with image zoom capability for viewing integration preview images * **Bug Fixes** * Fixed z-index layering issue with marketplace filter bar * **Refactor** * Redesigned marketplace detail page header with breadcrumb navigation * Updated integration image handling structure with enhanced metadata * Optimized dynamic loading for integration file viewers <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> |
||
|
|
1673012bc7 |
chore: Bump vulnerable dependencies (#46624)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated build tools and development dependencies across the project * Upgraded Vue framework and related tooling to latest versions * Updated TanStack React Start dependency * Refined dependency resolution settings to improve build stability and performance <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4c474068be |
feat: update @supabase/*-js libraries to v2.107.0 (#46586)
This PR updates @supabase/*-js libraries to version 2.107.0. **Source**: manual **Changes**: - Updated @supabase/supabase-js to 2.107.0 - Updated @supabase/auth-js to 2.107.0 - Updated @supabase/realtime-js to 2.107.0 - Updated @supabase/postgest-js to 2.107.0 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.107.0 ## 2.107.0 (2026-06-02) ### 🚀 Features - **auth:** remove navigator.locks-based mutex; introduce commit guard + dispose() ([#2392](https://github.com/supabase/supabase-js/pull/2392)) - **realtime:** allow httpSend to send binary payload ([#2400](https://github.com/supabase/supabase-js/pull/2400)) - **supabase:** update X-Client-Info to structured metadata format ([#2359](https://github.com/supabase/supabase-js/pull/2359)) ### 🩹 Fixes - **auth:** return AuthInvalidJwtError from getClaims for expired JWT ([#2395](https://github.com/supabase/supabase-js/pull/2395)) - **auth:** recognize ?error= redirects in implicit grant gate ([#2407](https://github.com/supabase/supabase-js/pull/2407)) - **auth): revert fix(auth:** encode client-id in oauth requests ([#2383](https://github.com/supabase/supabase-js/pull/2383), [#2417](https://github.com/supabase/supabase-js/pull/2417)) - **postgrest:** return a structured error for non-JSON body on successful responses ([#2398](https://github.com/supabase/supabase-js/pull/2398)) - **release:** pin workspace:* sibling deps before JSR publish ([#2418](https://github.com/supabase/supabase-js/pull/2418)) - **release:** publish gotrue-js legacy mirror via pnpm ([#2419](https://github.com/supabase/supabase-js/pull/2419)) ### ❤️ Thank You - Claude Opus 4.7 (1M context) - Claude Sonnet 4.6 - Eduardo Gurgel - Guilherme Souza - Katerina Skroumpelou @mandarini - Omar Al Matar @Bewinxed - youcef zr @youcefzemmar - youcefzemmar This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
1150d32462 |
fix: number inputs does not allow some editions (#46538)
## Problem Because we have controller inputs and zod validation on numbers, many of them cannot be cleared correctly as deleting their value resets it to `0`. ## Solution Update the `Input` component to allow those editions by always storing and displaying the user entered value ## How to test - Open the webhook page and add/edit one - Clear its timeout value and observe that it is not reset to `0` - Same for: - Database network restrictions - API settings max rows - Disk size modal <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized numeric form input handling across examples, settings, and modals — inputs now rely on form bindings and schema coercion for consistent parsing and simplified behavior. * **Chores** * Added form resolver utilities and a user-event testing library to development dependencies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b79a64e301 |
feat: add Realtime Flow component (#44273)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature, docs update ## What is the new behavior? This PR introduces a new `RealtimeFlow` component and hook to the UI library for building collaborative React Flow with Supabase Realtime: - keeps nodes and edges in sync across multiple connected clients in real time - uses Yjs with `@supabase-labs/y-supabase` to propagate flow updates - supports optional persistence, so a flow can be restored from previously saved shared state ## Additional context https://github.com/user-attachments/assets/90d3a381-6f9c-427f-a493-5d91c2141462 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Collaborative "Realtime Flow" diagram editor with syncing overlays and a dual-view demo component * Interactive demo page and registry example for live editing (add/remove/rename nodes) * Framework-ready registry packages for Next.js, React, React Router, and TanStack * **Documentation** * Comprehensive docs added for Next.js, React, React Router, and TanStack (usage, persistence, hook API) * **Chores** * Added runtime dependency for the flow component package [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/44273) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
91c928e345 |
feat: update @supabase/*-js libraries to v2.106.2 (#46324)
This PR updates @supabase/*-js libraries to version 2.106.2. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.106.2 - Updated @supabase/auth-js to 2.106.2 - Updated @supabase/realtime-js to 2.106.2 - Updated @supabase/postgest-js to 2.106.2 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.106.2 ## 2.106.2 (2026-05-25) ### 🩹 Fixes - **auth:** restore signup user response ([#2391](https://github.com/supabase/supabase-js/pull/2391)) - **misc:** add react-native export condition for Hermes-safe resolution ([#2393](https://github.com/supabase/supabase-js/pull/2393)) ### ❤️ Thank You - Myroslav Hryhschenko @BLOCKMATERIAL - Vaibhav @7ttp ## v2.106.1 ## 2.106.1 (2026-05-20) ### 🩹 Fixes - **auth:** encode client-id in oauth requests ([#2383](https://github.com/supabase/supabase-js/pull/2383)) - **misc:** hide dynamic import from hermesc ([#2381](https://github.com/supabase/supabase-js/pull/2381)) ### ❤️ Thank You - Etienne Stalmans @staaldraad - Katerina Skroumpelou @mandarini This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
cadfc8731c |
docs: realtime chat/infinite query vue&nuxt (#44426)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This PR is the final PR for Supabase UI Vue&Nuxt with the Realtime Chat and Infinite Query. ## Additional context Initiative by Terry <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Realtime Chat now available for Vue and Nuxt.js frameworks with full documentation and composables * Added Infinite Query composable for Vue with comprehensive guides * **Documentation** * New Realtime Chat documentation pages for Vue and Nuxt.js * New Infinite Query documentation for Vue * Updated framework support in documentation navigation <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Terry Sutton <saltcod@gmail.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
cc0b2d3d21 |
chore(studio): remove require-safe-sql-fragment ESLint rule (#46079)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / chore. ## What is the current behavior? A custom type-aware ESLint rule (`studio/require-safe-sql-fragment`) enforces that the `sql` argument to `executeSql` is a `SafeSqlFragment`. It runs in a separate `eslint.type-checks.config.cjs` and a dedicated CI ratchet step, and pulls in `@typescript-eslint/utils` as a direct dev dependency. ## What is the new behavior? `SafeSqlFragment` enforcement is now handled entirely by TypeScript compilation. The ESLint rule, its dedicated config, the ratchet baselines for it, the CI step, and the `@typescript-eslint/utils` direct dev dependency have all been removed. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Simplified development linting workflow by removing type-aware ESLint checks and associated rule files. * Cleaned up ESLint configuration and dependencies in the studio application. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46079?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ba34c1f6e9 |
feat: update @supabase/*-js libraries to v2.106.0 (#46068)
This PR updates @supabase/*-js libraries to version 2.106.0. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.106.0 - Updated @supabase/auth-js to 2.106.0 - Updated @supabase/realtime-js to 2.106.0 - Updated @supabase/postgest-js to 2.106.0 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.106.0 ## 2.106.0 (2026-05-18) ### 🚀 Features - **supabase:** W3C/OpenTelemetry trace context propagation ([#2163](https://github.com/supabase/supabase-js/pull/2163)) ### 🩹 Fixes - **auth:** return null user and session for email_change single-confirmation verifyOtp ([#2378](https://github.com/supabase/supabase-js/pull/2378)) - **release:** mark @supabase/tracing private and snapshot it for JSR ([#2370](https://github.com/supabase/supabase-js/pull/2370)) - **storage:** make StreamDownloadBuilder implement Promise and memoize executor ([#2367](https://github.com/supabase/supabase-js/pull/2367)) ### ❤️ Thank You - Claude Sonnet 4.5 - Guilherme Souza - Katerina Skroumpelou @mandarini - oniani1 This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
9dc3998fa0 |
RLS Tester sandbox environment (#45839)
## Context Resolves FE-3221 Heavily inspired by what @filipecabaco has done previously here: https://github.com/supabase/supabase/pull/45360 This PR explores the use of pglite to set up a sandbox for RLS testing, which will pave the way for testing mutation based queries so to ensure no disruption to the actual database. Sandbox can be set up within the RLS tester panel as such: <img width="500" alt="image" src="https://github.com/user-attachments/assets/0cfdf8e4-dd99-4dee-ac00-39a32b375c07" /> Which the sandbox will mimic the project's database to the bare minimum required - entities from the `public` schema are copied over (types, tables, functions, policies) - `auth` schema is pseudo setup with `SANDBOX_SETUP_STATEMENTS` - Enough to support role impersonation + querying tables with references to the auth schema (e.g users table) - data is seeded up to 100 rows for each table - More info RE limitations in the last section below Once sandbox is ready, you'll see this UI where you can either leave the sandbox, or re-sync the sandbox from the actual database <img width="500" alt="image" src="https://github.com/user-attachments/assets/d07ce55f-5bc8-4722-8ce9-898b9b458f9b" /> Changes are currently feature flagged, so won't be available publicly just yet until things are ironed out and ready ## To test - [ ] Verify that setting up sandbox works - [ ] Verify that you can query your sandbox, and queries do not touch the actual database (can verify that we're not sending HTTP requests to the /query endpoint) - [ ] Verify correctness of RLS tester as well, should match correctness with testing against actual DB - [ ] Verify that re-syncing sandbox picks up changes - Can test by updating your policies that will affect the output of your select query - e.g SELECT for `authenticated`, change from just `true` to `false` - [ ] RLS tester should work as per normal (against actual DB) with the feature flag off with no additional overhead Let me know of any edge cases you might run into while testing ## Known quirks that will be addressed subsequently Leaving these for now just to not bloat this PR further - Pglite schema needs to be re-synced if updating RLS policies while testing, to ensure that pglite gets the updated policies. Will think about how to make this more seamless - Sandbox has its own limitations, will need to add a dialog to inform users how the sandbox works and what limitations to note of - e.g only the auth schema is mimicked - so policies that reference storage helpers won't work (although i think auth is probably the main use case and the rest might be niche) - We can slowly expand tho where required - Eventually we'll also move forward with figuring out testing mutation queries with this sandbox <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * RLS tester gains an isolated Postgres sandbox with schema/seed import, start/refresh/exit controls, and pre-populated auth data. * Sandbox management UI with setup, loading, active, and error states; refresh and destroy actions. * **Bug Fixes** * Role impersonation now keeps the PostgREST role set to anon while the tester sheet is open. * **Chores** * Content Security Policy updated to allow sandbox/connectivity endpoints. * **Style** * Minor sheet styling adjustment (top border). <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45839) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
86a3f8b03d |
chore: upgrade to react-19 (#45886)
- Most changes are related to either types or `useRef` usages (it now requires an initial value). - also updated `vaul` to its latest version and haven't noticed any change ([design-system demo](https://design-system-git-react-19-supabase.vercel.app/design-system/docs/components/drawer)) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Upgraded workspace to React 19. * **Bug Fixes** * Improved null-safety and ref handling across editors, UI components, shortcuts, and markdown/image rendering to reduce runtime errors. * Safer event/timeout/interval cleanup and more robust command/context handling. * **Chores** * Bumped vaul dependency versions. * **Documentation** * Type and TypeScript accuracy improvements for clearer developer feedback. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45886) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
640869da47 |
chore: Clean up remaining Tailwind code (#45925)
This PR finishes the Tailwind migration by doing some minor fixes: - Remove `@radix-ui/colors` and inline the color values into the color definitions. The default Tailwind colors are unset and replaced by our own color set (both in light and dark variants). - Remove the `colorA` colors because they were used with alpha values. They were unused and Tailwind v4 supports alpha values natively. - Replace the `hit-area` JS config with the original CSS config from https://bazza.dev/craft/2026/hit-area. The original config was migrated to JS config to work with Tailwind v3. Now that we're on v4, we can just use the source format. - Remove the `motion-safe-transition` plugin since it's now [supported natively by Tailwind](https://tailwindcss.com/docs/transition-duration#supporting-reduced-motion) - Replace `tailwindcss-animate` with `tw-animate-css`. The old plugin was unmaintained and using JS config. The new one should be a drop-in replacement. - Remove all scripts for generating colors, they're not needed anymore, all values are hardcoded. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added hit-area debugging and sizing utilities for enhanced layout control. * **Refactor** * Restructured color system to use hand-edited CSS variables with inlined values for improved performance and maintainability. * Migrated animation utilities to a new framework. * **Style** * Enhanced motion-reduced animations with improved transition behavior. * Adjusted sidebar layout styling for better visual presentation. * **Chores** * Updated animation dependencies. * Removed legacy color generation scripts. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45925) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
d4079083fc |
chore(studio): drop @supabase/postgres-meta in favor of @supabase/pg-meta (#45844)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / dependency cleanup. ## What is the current behavior? `apps/studio` lists both `@supabase/pg-meta` (workspace package) as a runtime dep and `@supabase/postgres-meta` (external npm package, `^0.64.4`) as a devDependency. The external package is used only for type imports across 44 files — there is no runtime usage and no codegen pipeline that needs it. ## What is the new behavior? Every `Postgres*` type import (`PostgresTable`, `PostgresColumn`, `PostgresPolicy`, `PostgresTrigger`, `PostgresView`, `PostgresMaterializedView`, `PostgresForeignTable`, `PostgresSchema`, `PostgresPublication`, `PostgresRelationship`, `PostgresPrimaryKey`) is replaced with its `PG*` counterpart from `@supabase/pg-meta`, and the external dep is removed from \`apps/studio/package.json\`. Top-level type re-exports were added to \`packages/pg-meta/src/index.ts\` so consumers can import directly from the package root. Two latent issues surfaced by the stricter pg-meta types are also fixed: - \`data/foreign-tables/foreign-tables-query.ts\` was casting foreign-table results as \`PostgresView[]\`; corrected to \`PGForeignTable[]\`. - \`pg-meta\`'s \`PGTrigger\` Zod schema declared \`orientation\`/\`activation\` as \`z.string()\`, inconsistent with pg-meta's own \`getDatabaseTriggerUpdateSQL\` helper that requires the narrow literal unions; tightened to \`z.enum\`. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated internal TypeScript type definitions across the codebase to use the latest type system from `@supabase/pg-meta`. * Removed `@supabase/postgres-meta` dependency. * Enhanced type validation for database triggers and schemas to enforce stricter constraints. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45844) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
71e94a1590 |
Add partner integration guide and mermaid diagrams (#45730)
- **Draft** - **Update** - **feat: add beautiful-mermaid and integration flow diagrams** - **Make mermaid theme match site** <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Mermaid diagram rendering in docs with themed SVG output. * **Documentation** * Added "Supabase Partner Integration Guide" covering simple and signed-redirect flows, JWT verification, sequence diagrams, and key guidance. * Updated site navigation to include the new partner integration guide. * **Chores** * Added Mermaid rendering dependency. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45730) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
380c917b94 |
chore: Bump vulnerable dependencies (#45876)
- Bump various vulnerable dependencies, `nitropack`, `mermaid`, `hono`, `protobufjs`, `fast-xml-builder` and `fast-uri`. - Add `babel/core` to `studio` to stabilize the dependency resolving for `studio`. - Also deduped `cheerio`, `c12`, `browserslist`, `unstorage` and `@mdx-js/mdx` since they were present as multiple similar versions. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added development dependency for the studio application build tooling * Updated workspace configuration to refine dependency exclusion settings <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45876) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0abe792889 |
chore: Migrate the main Tailwind JS config to CSS (#45686)
This PR migrates the JS config for Tailwind into a CSS config. As such, all variables have been defined as CSS variables and they're using the specialized Tailwind syntax for generating utility classes. Beside the migration, these changes were also added: - Added `tailwind.config.css` to few packages to make the Tailwind Intellisense work. - Migrated away from Radix style color classes to our defined classes, the values will remain the same. - Most of the CSS is generated by scripts, they'll be removed in next PRs. * Removed redundant `border-light` classes from several components since it was undefined. * Removed redundant `text-strong` classes from several components since it was undefined. How to test: - Open all apps, compare the UI (mainly colors) to builds from #45417 and try to find a difference. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Harmonized color variable usages and updated UI color references (affects palettes, charts, gradients, hero illustrations, and scrollbars). * Tweaked border, tab, and selection visuals across components. * **New Features** * Added a suite of theme animations and refined typography presets used by site prose and docs. * **Refactor** * Overhauled Tailwind/theme configuration and color token generation for more consistent theming. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d143571586 |
feat(assistant): trace-level scorers + server-side tool execution with needsApproval (#45654)
## Motivation When Assistant runs a potentially destructive tool like `execute_sql`, it stops the LLM request and prompts for client-side approval and execution of the tool. After approval, a second request kicks off under a separate trace. This has made scoring and [Topics](https://www.braintrust.dev/blog/topics) classification challenging, as the generated `output` is split across stateless requests. The [span-level scoring](https://www.braintrust.dev/docs/evaluate/custom-code#score-spans) approach we've used thusfar (after the LLM call, we massage the result into an `output` payload that's stuck onto the root span) has been cumbersome and led to invalid scores / topics where only part of the assistant response is considered. It's also inefficient, as we're duplicating potentially large info (like the `search_docs` output) that already exists within the trace. An alternative to scoring spans is to [score traces](https://www.braintrust.dev/docs/evaluate/custom-code#score-traces). Braintrust [best practices](https://www.braintrust.dev/docs/evaluate/score-online#best-practices) advise: > Use span scope for evaluating individual operations or outputs. Use trace scope for evaluating multi-turn conversations, overall workflow completion, or when your scorer needs access to the full execution context. We've also received [direct guidance](https://supabase.slack.com/archives/C05QYJBLX89/p1777925770927149?thread_ts=1777905716.911979&cid=C05QYJBLX89) from their team to use this approach. ## Changes Migrates eval scorers from custom `AssistantEvalOutput` shape to trace-level scoring via `trace.getThread()` / `trace.getSpans()`, with thread parsing that scores the full latest Assistant turn and passes prior conversation separately where relevant. Moves `execute_sql` and `deploy_edge_function` from client-side execution after approval to AI SDK `needsApproval` + server-side `execute()`. SQL results returned to the model are gated by AI opt-in level, so row data is only included with `schema_and_log_and_data`; otherwise the tool returns the no-data-permissions sentinel. Adds `metadata.isFinalStep` to disambiguate multiple LLM requests within an "assistant" turn due to tool call requests/responses. For online evals, this means we should configure automations to only score traces with `metadata.isFinalStep = true` to ensure we're judging the complete generated response. Other minor kaizen changes: - Renamed `promptProviderOptions` to `systemProviderOptions` to clarify that this is associated with the "system" message and disambiguate from the root `providerOptions` - Adds `evals/trace-utils.ts` to handle Zod validation of the `unknown` span shapes from Braintrust, to more easily access typed inputs/output on tool spans. - Bumps AI SDK floor version `^6.0.116` → `^6.0.174` - Tweaked the "Conciseness" scorer to not unfairly dock points for the new `[called tool_name]` labels in serialized assistant response ## Verification In the studio staging build, I asked Assistant to create a todos table with 3 sample todos. I manually approved the `execute_sql` call and saw Assistant generate text before & after the call. In Braintrust I verified two traces were produced (see [filtered logs](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?v=Staging&tvt=trace&search={%22filter%22:[{%22text%22:%22metadata.environment%2520%253D%2520%27staging%27%22,%22label%22:%22metadata.environment%2520%253D%2520%27staging%27%22,%22originType%22:%22btql%22},{%22text%22:%22%2560Chat%2520ID%2560%2520%253D%2520%25221cb2ac45-e5e7-458c-9da4-3bf6863b8842%2522%22,%22label%22:%22Chat%2520ID%2520equals%25201cb2ac45-e5e7-458c-9da4-3bf6863b8842%22,%22originType%22:%22form%22}]})), the first with `metadata.isFinalStep = false` and the second with `metadata.isFinalStep = true`. In the Braintrust staging scorers, I ran the preview Completeness scorer on the second trace and verified it sees the complete Assistant response including markers for tool calls ([link to trace](https://www.braintrust.dev/app/supabase.io/p/Assistant%20(Staging%20Scorers)/trace?object_type=project_logs&object_id=b5214b62-ad1e-4929-9d5b-40b1daebe948&r=0ed0a4f8-8aff-4a34-bb1d-1df1d88a5070&s=ff9015f8-6bf7-4ab3-83a9-ca4e69e27e82)) <img width="1193" height="960" alt="CleanShot 2026-05-07 at 11 27 10@2x" src="https://github.com/user-attachments/assets/509d4858-c3a1-4068-986d-3aa4d5617d1a" /> I also tested the `deploy_edge_function` workflow and verified it still prompts for permission and warns on deployment of existing functions. **References** - https://www.braintrust.dev/docs/evaluate/custom-code#score-traces - https://ai-sdk.dev/docs/ai-sdk-core/tools-and-tool-calling#tool-execution-approval Supercedes https://github.com/supabase/supabase/pull/45556 and https://github.com/supabase/supabase/pull/45339 Closes AI-473 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Tool actions (SQL execution, edge-function deploy) now require explicit user Approve/Deny before proceeding. * **Improvements** * Assistant pauses for approval responses before sending follow-ups, giving clearer control over risky actions. * Deploy/replace flows show confirmation and clearer replace warnings. * Evaluation/scoring updated to use richer trace data for more accurate assistant performance signals. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
da44ab3088 |
feat(www): fetch partner integration listings from marketing-db (#45725)
This adds a layer of indirection to fetch partner integration listings for the marketing page from the new Marketplace DB, which will allow us to maintain these listings via the same admin UI we're building for in-app integration listings. Fixes INT-102 |