5136 Commits
Author SHA1 Message Date
AnaandAna 8d0c129dd8 blog: Supabase joins the Stripe Projects developer preview (#43982)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?
New blog post for Stripe Projects

## What is the current behavior?
N/A

## What is the new behavior?
Adds a new blog post: "Supabase joins the Stripe Projects Developer
Preview" and adds Gregor Vand and Ana Mogul to authors.json.

---------

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-03-20 12:19:21 +01:00
Prashant Sridharan 1e12f93fde Updated webinar pages with YouTube recording links (#44003)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Updated webinar landing pages with recording of the event on YouTube
2026-03-19 22:35:09 +00:00
Danny WhiteandAlan Daniel 48b96e8a79 fix(www): use imgSocial for blog OG images (#43842)
## What kind of change does this PR introduce?

- Bug fix that resolves DEPR-396
- Additional improvements to blog post image handling

## What is the current behavior?

Blog post Open Graph metadata often prefers `imgThumb` over `imgSocial`,
so social previews on X, iMessage, and similar surfaces can render the
on-site thumbnail instead of the intended social image.

The image selection and path-normalization rules are also duplicated
across blog surfaces, which makes the precedence rules easy to drift.

## What is the new behavior?

- Centralizes blog image handling in `apps/www/lib/blog-images.ts`
- Uses `imgSocial` first, then `imgThumb`, for blog OG/Twitter metadata
- Uses `imgThumb` first, then `imgSocial`, then the placeholder, for
blog thumbnails and post hero images
- Normalizes relative blog image paths into absolute URLs for metadata
- Adds warning-only validation during content reads/builds for partial
or malformed `imgSocial` / `imgThumb` config
- Updates a few recent blog posts so `imgThumb` is a thumbnail-only
asset instead of duplicating the social image

## Additional context

- Replaces #42319 with the additional above fixes
- Added unit coverage for the shared image helper

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-03-19 02:45:11 +00:00
Alan DanielandClaude 56fdd5584b Update careers page stats and values for 2026 (#43877)
- Stats: 280+ team members, 55+ countries, 20+ languages, $500M raised,
540,000+ community
- Values: Egoless, Kaizen Mindset, Truth Seeking, Batteries Included,
Undeniable

Slack thread:
https://supabase.slack.com/archives/C0429V78ACX/p1773767300740889?thread_ts=1773766991.320389&cid=C0429V78ACX

https://claude.ai/code/session_01T8W44eQfosStneyEFhTCW8

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.

Co-authored-by: Claude <noreply@anthropic.com>
2026-03-18 12:03:12 -04:00
Alan Daniel ee8cb336af new go blocks (#43771)
### FAQ (`type: 'faq'`)
Accordion-style FAQ with expand/collapse. Each item has a `question` and
`answer`. Click to toggle — only one open at a time.

<img width="1309" height="610" alt="Screenshot 2026-03-13 at 17 31 31"
src="https://github.com/user-attachments/assets/289c8a12-3835-4f64-bbe6-fb7095df4e7c"
/>

### Code Block (`type: 'code-block'`)
Syntax-highlighted code display using shiki with custom Supabase
dark/light themes. Supports:
- **Single file** — `code` + optional `filename` + `language`
- **Multi-file** — `files: [{ filename, code, language }]` with
clickable tabs
- Line numbers via CSS counters
- All highlighting runs at build time (server component), only tab
switching is client-side

<img width="1283" height="415" alt="Screenshot 2026-03-13 at 17 32 07"
src="https://github.com/user-attachments/assets/9cc9a215-d5c9-47c9-8e21-c1dd3beca4ba"
/>

### Steps (`type: 'steps'`)
Numbered step-by-step guide with a vertical timeline connector. Each
item has `title` and either a plain `description` string or a `content`
slot accepting any React node (e.g. images, code blocks).

<img width="1119" height="810" alt="Screenshot 2026-03-13 at 17 32 20"
src="https://github.com/user-attachments/assets/cb67aaab-9ed4-42e2-bf1c-8d836024e469"
/>

### Quote (`type: 'quote'`)
Centered testimonial block with `quote`, `author`, optional `role`, and
optional `avatar` image.

<img width="1095" height="238" alt="Screenshot 2026-03-13 at 17 32 37"
src="https://github.com/user-attachments/assets/356a39ca-9f65-4414-bf77-6060993594a4"
/>
2026-03-17 15:13:21 -04:00
Ivan VasilovandJoshen Lim 9fa96977be chore: Minor prettier fixes (#43849)
This PR fixes some prettier issues:
- Bump and unify all prettier versions to 3.7.3 across teh whole repo
- Bump the SQL prettier plugin
- When running `test:prettier`, check `mdx` files also
- Run the new prettier format on all files

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-03-17 11:17:42 +01:00
Stephen Morgan d49da89517 feat: update to DPA Q1 2026 (#43843)
Only one change to this DPA in the addition of Braintrust as a
sub-processor

Fixes SEC-757
2026-03-17 07:34:40 +01:00
AnaandAna Mogul dc04437fde fix(www): correct feature statuses, MCP Server copy, and self-hosted flags (#43223)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

A content/data fix: correcting stale feature metadata on the marketing
features page and docs feature status table.

## What is the current behavior?

Several features in features.tsx (supabase.com/features) have incorrect
stage or self-hosted availability values that are out of sync with docs.

## What is the new behavior?

branching
- stage updated to Beta

vault
- stage updated to Public Alpha

jwt-signing-keys
- availableOnSelfHosted set to true

persistent-storage
- docs URL corrected to /guides/functions/ephemeral-storage
- env var names corrected to S3FS_ACCESS_KEY_ID, S3FS_SECRET_ACCESS_KEY,
S3FS_REGION, S3FS_ENDPOINT_URL

features.mdx
- PrivateLink row added to the Platform section (beta, N/A for
self-hosted)

mcp-server
- removed "upcoming" from OAuth benefit (OAuth is now live), updated PAT
FAQ (OAuth is now default, PAT only needed for CI/CD), updated
self-hosted FAQ (self-hosted is supported via
/guides/self-hosting/enable-mcp)

## Additional context

N/A

---------

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-16 18:47:30 -04:00
Prashant Sridharan 5528817602 Figma webinar pages (#43779) 2026-03-16 16:15:01 +00:00
Pamela Chia 4a4fe253ce feat(www,studio): privacy policy amendments — advertising, cookie disclosure, banner (#43681) 2026-03-16 21:49:02 +09:00
AnaandAna 614b2071e9 fix: remove date reference from BYOC early access page (#43725)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Removing timeline from BYOC early access page

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-03-14 12:00:04 -04:00
Alan Daniel 75857039f7 add blog url button support to features page. (#43767)
This pr adds a blog post button support to /features pages.

| Before | After |
|--------|--------|
| <img width="504" height="234" alt="Screenshot 2026-03-13 at 16 09 50"
src="https://github.com/user-attachments/assets/62672e22-2b6e-478a-8d56-a1ca7b4c83d1"
/> | <img width="450" height="253" alt="Screenshot 2026-03-13 at 16 08
44"
src="https://github.com/user-attachments/assets/d45550cc-47a2-457e-bb77-abb3add54073"
/> |
2026-03-13 17:04:55 -04:00
Alan Daniel 9c650cca60 add partners section to webinar page (#43761)
Add speakers section to webinar page.

| Before | After |
|--------|--------|
| <img width="685" height="406" alt="Screenshot 2026-03-13 at 15 50 27"
src="https://github.com/user-attachments/assets/7997c452-0d6a-422b-b97b-dffabf236a75"
/> | <img width="711" height="515" alt="Screenshot 2026-03-13 at 15 50
07"
src="https://github.com/user-attachments/assets/21356245-0831-43f2-b780-44bcf7e73360"
/> |
2026-03-13 20:46:22 +00:00
Alan Daniel 3ad2779236 newsletter form in /security page (#43768)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

test at /security page.
2026-03-13 16:43:28 -04:00
supabase-supabase-autofixer[bot]anddnywh 8e4c0986c7 Changes by create-pull-request action (#43460)
Automated changes by
[create-pull-request](https://github.com/peter-evans/create-pull-request)
GitHub action

Co-authored-by: dnywh <3104761+dnywh@users.noreply.github.com>
2026-03-13 12:09:59 +11:00
Sean Oliver b041ebfaa5 feat(www): Phase 2 — enable cookie stamping on /dashboard and /docs paths (#43677) 2026-03-12 15:23:07 -07:00
Alan Daniel c42a14ebfc support multiple columns on featured grid in go pages (#43717)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.
2026-03-12 12:00:31 -06:00
Prashant Sridharan 8935aaf5f1 Added new conference go pages with speaker and slide download callouts (#43695) 2026-03-12 13:43:44 +00:00
Jeremias Menichelli b2fdc7687f feat: Implement telemetry on Search commands (#43563) 2026-03-12 14:34:55 +01:00
AnaandAna 9c5626b514 fix(www): update log drains pricing from $10 to $60 in blog post (#43669)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update wrong pricing on blog post

## What is the current behavior?

Pricing is shown as $10 when it should be $60

## What is the new behavior?

Pricing is show as $60

## Additional context

N/A

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-03-11 15:20:19 -04:00
Daniel Nunns c542bf8984 fix(docs): Correct repo_url for Huggingface Image Captioning example (#43445) 2026-03-11 13:20:13 +00:00
973bacf783 docs: Data API IA (#42417)
*Summary*
- reorganize the navigation menu to highlight modules, consolidate API
security content, and move guide entries (auto-generated docs, type
generation, security topics) to the intended sections
- relocate the Data API hardening and custom claims RBAC guides into the
API subtree, updating internal references and redirects, and fixing
cross-links (including adjusting the Security reference order)
- adjust data API topic references (e.g., securing guide and role
management) to point to the new paths and ensure the helper link
ordering follows the requested layout

*Testing*
- Not run (not requested)

Change 1

<img width="1286" height="576" alt="image"
src="https://github.com/user-attachments/assets/d903e9b0-bbfc-403f-bcb9-eee540e466db"
/>

Change 2

<img width="1176" height="666" alt="image"
src="https://github.com/user-attachments/assets/82b3ea4c-b8d4-4cb9-ad90-6c39c8a1a997"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reorganized API documentation structure, consolidating REST and
GraphQL API guides under a dedicated API section.
* Moved security-related guides to API documentation paths for better
organization.
* Implemented automatic redirects for old documentation links to new
locations.
* Updated navigation menu to reflect the restructured documentation
layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-03-11 14:11:26 +01:00
Jordi EnricandClaude 7848dafdd9 Update company page stats (#43635)
- Developers: 1.7M → 7M+
- GitHub Stars: 79K → 98K+
- Twitter Followers: 140K → 190K+
- Discord: 34K → 47K+

https://claude.ai/code/session_01VKuCJaCmDttAT8iHXpiU9h

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.

Co-authored-by: Claude <noreply@anthropic.com>
2026-03-11 11:54:06 +01:00
Riccardo BusettiandChris Chinchilla 1201f1cdf9 ref(docs): Remove Analytics Buckets destination from docs (#43590)
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-03-11 10:03:25 +00:00
Prashant SridharanandAlan Daniel 8fe62a5715 Updated ETL blog post and added speakers to webinar (#43602)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Modified the old Supabase ETL blog post
- Added two new speakers to an upcoming webinar

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-03-10 17:58:14 +00:00
af47a2d010 experiment:pricing feedback iteration on calculator (#42451)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — A/B experiment for a new pricing calculator on the `/pricing`
page, gated behind a PostHog feature flag.

## What is the current behavior?

The pricing page shows a single compute pricing section
(`PricingComputeSection`) to all visitors with no experimentation
support.

## What is the new behavior?

- Introduces a **pricing calculator A/B experiment**
(`pricingCalculatorExperiment`) using PostHog feature flags evaluated
client-side.
- **Control variant**: Renders the existing `PricingComputeSection` (no
change).
- **Test variant**: Renders a new `NewPricingComputeSection` with:
  - A plan selector toggle (Pro / Team)
  - An interactive compute calculator with slider-based instance sizing
  - Ability to add/remove multiple project instances
  - Live monthly cost estimate breakdown (plan + compute - credits)
  - Expandable compute pricing table with detailed specs
- Adds `getFeatureFlag` and `onFeatureFlags` methods to the shared
`PostHogClient` for client-side flag evaluation on www pages (where
server-side evaluation lacks full person context).

## Additional context

- The experiment is scoped to the `/pricing` page only.
- New components (`NewPricingComputeSection`,
`NewComputePricingCalculator`) are created alongside the existing ones —
the control path is completely untouched.
- Feature flag evaluation happens client-side because www pages don't
have full person context on the server.
- Telemetry type `PricingCalculatorExperimentExposedEvent` is added to
`telemetry-constants.ts`.

---------

Co-authored-by: Sean Oliver <882952+seanoliver@users.noreply.github.com>
Co-authored-by: Mert YEREKAPAN <mertyerekapan@gmail.com>
Co-authored-by: Mert YEREKAPAN <33198490+myerekapan@users.noreply.github.com>
2026-03-10 13:57:52 +01:00
Sean Oliver 8ebbad3a5b feat(growth): expand www middleware to /dashboard and /docs (Phase 1 - instrumentation only) (#43413)
## Problem

The `_sb_first_referrer` cookie isn't working. The www middleware
matcher explicitly excludes `/dashboard` and `/docs`, so the cookie
never gets stamped for Studio or Docs traffic. PostHog confirmed: only 1
event with `first_referrer_cookie_present=true` out of ~46.5M Studio
pageviews in the last 7 days.

## Background: what the matcher does

In Next.js, the `matcher` config controls which incoming requests the
middleware function even runs on. If a path doesn't match, the
middleware is skipped entirely — the request passes through untouched.
If it matches, the middleware runs and can mutate the response (set
cookies, headers, etc.).

This matters because Studio's SPA navigation works via silent
`/_next/data/` JSON fetches. If middleware runs on those requests and
returns `NextResponse.next()` with any mutations, it breaks those
fetches and causes full page reloads instead of client-side transitions.

## What we tried before

| PR | www runs on `/dashboard`? | Studio `proxy.ts` runs on all routes?
| Result |
|---|---|---|---|
| **#42768** (Attempt 1) | ✅ Yes — and also intercepts `_next/data` | ✅
Yes — `matcher` config removed, stamps cookie everywhere | Full page
reloads in Studio |
| **#43129** (Full revert) | ❌ No — www middleware deleted entirely | ❌
No — restored to `matcher: '/api/*'` only | Back to baseline, no cookie
stamping anywhere |
| **#43153** (Attempt 2) | ❌ No — `/dashboard` explicitly excluded | ✅
Yes — `matcher` config removed again, stamps cookie everywhere | Full
page reloads in Studio again |
| **#43189** (Attempt 3) | ❌ No — same as #43153 | ✅ Yes — `matcher`
config still removed, cookie stamping made conditional | Still broken |
| **#43190** (Ivan's fix) | ❌ No — `/dashboard` still excluded | ❌ No —
restored to `matcher: '/api/*'` only | Works — but cookie never stamps
for `/dashboard` traffic |
| **#43413** (this PR) | ✅ Yes — sets diagnostic cookie only, no
attribution stamping yet | ❌ No — unchanged, still `matcher: '/api/*'`
only | ❓ Untested in prod |

The common factor in every failure: Studio's `proxy.ts` ran on all
routes (including `_next/data` requests), which broke SPA navigation.
This PR is the first one that runs www middleware on `/dashboard` while
Studio's `proxy.ts` stays in its original narrow `/api/*` scope.

## What changed

This is Phase 1 of a two-phase rollout. We remove `dashboard|docs` from
the matcher's negative lookahead so www middleware runs on those paths —
but instead of stamping cookies, we set a short-lived (60s) diagnostic
cookie `_sb_mw_diag` on `/dashboard` and `/docs` requests.

The diagnostic cookie encodes
`hit=1&would_stamp={0|1}&has_cookie={0|1}`, which Studio telemetry reads
on the initial pageview and reports to PostHog as `mw_diag_hit`,
`mw_diag_would_stamp`, and `mw_diag_has_existing_cookie` properties.

A cookie rather than a header because response headers aren't readable
by JS. It also tests the actual Set-Cookie mutation path that Phase 2
will use (which is what Next.js issue #41885 is specifically about).

Phase 1 answers two key questions before we commit to Phase 2:
1. Does expanding the matcher break Studio SPA navigation?
2. What % of /dashboard arrivals would get a first-referrer cookie
stamped in Phase 2?

## Phase 2 readiness criteria

**Important caveat**: `mw_diag_*` data reflects consented users only and
may under-represent first-visit anonymous traffic. The Phase 2 decision
should account for this — the actual middleware execution rate is likely
higher than what PostHog reports.

### PostHog query spec

**Middleware execution rate**: Of all Studio initial pageviews on
`/dashboard` or `/docs` paths, what percentage have `mw_diag_hit =
true`? Expected: >= 90%. Below 70% warrants investigation (could
indicate edge caching bypassing middleware, or a matcher configuration
issue).

```
Filter: event = "$pageview" AND (current_url contains "/dashboard" OR current_url contains "/docs")
Breakdown: mw_diag_hit (true vs null/missing)
Metric:    count(mw_diag_hit = true) / count(all) * 100
```

**Would-stamp rate**: Of events with `mw_diag_hit = true`, what
percentage have `mw_diag_would_stamp = true`? This tells us what
percentage of Phase 2 traffic would actually get a cookie stamped. No
hard threshold — unexpected values (< 5% or > 95%) suggest a logic bug
worth investigating before Phase 2.

```
Filter: event = "$pageview" AND mw_diag_hit = true
Breakdown: mw_diag_would_stamp (true vs false)
Metric:    count(mw_diag_would_stamp = true) / count(all) * 100
```

**Existing cookie rate**: Of events with `mw_diag_hit = true`, what
percentage have `mw_diag_has_existing_cookie = true`? This tells us how
many users already have the cookie from a prior www visit.

```
Filter: event = "$pageview" AND mw_diag_hit = true
Breakdown: mw_diag_has_existing_cookie (true vs false)
Metric:    count(mw_diag_has_existing_cookie = true) / count(all) * 100
```

### Go / no-go threshold table

| Signal | Go | Investigate | No-Go |
|---|---|---|---|
| `mw_diag_hit` rate (% of /dashboard+/docs pageviews) | >= 90% | 70-90%
| < 70% |
| SPA navigation errors (Sentry / Vercel logs) | No increase | < 0.1%
increase | > 0.5% increase |
| Middleware p99 latency (Vercel function logs) | < 50ms added |
50-100ms | > 100ms |
| Sample volume in first 24h | > 1,000 events | 100-1,000 (extend
window) | < 100 (insufficient data) |

## Changes

- `apps/www/middleware.ts`: Removed `dashboard|docs` from matcher; added
`isDashboardOrDocs` guard that sets `_sb_mw_diag` diagnostic cookie
instead of stamping attribution
- `apps/www/middleware.test.ts`: 12 tests covering cookie stamping on
www paths, diagnostic cookie encoding for all scenarios (external
referrer, direct nav, internal referrer, existing cookie)
- `packages/common/first-referrer-cookie.ts`: Exported
`MW_DIAG_COOKIE_NAME`, `MwDiagData` type, and `parseMwDiagCookie()`
helper
- `packages/common/telemetry.tsx`: Reads `_sb_mw_diag` on initial Studio
pageview; reports `mw_diag_*` properties to PostHog

## Testing

Unit tests pass (13/13 www, 31/31 first-referrer-cookie). Production
validation needed:

- [ ] Studio SPA navigation works (tab changes, SQL editor, no full page
reloads)
- [ ] PostHog shows `mw_diag_hit = true` on Studio initial pageviews
- [ ] `mw_diag_would_stamp` distribution looks reasonable before
enabling Phase 2
- [ ] Monitor 24h before Phase 2

Ref: GROWTH-625 / GROWTH-668
2026-03-09 11:47:20 -07:00
Danny White 18bee64d98 www(chore): remove State of Startups flag (#43423)
## What kind of change does this PR introduce?

Remove feature flag.

## What is the current behavior?

The [State of Startups](https://supabase.com/state-of-startups) page
instantly redirects to the homepage rather than staying put.

## What is the new behavior?

The [State of Startups](https://supabase.com/state-of-startups) page
rightfully loads.

## Additional context

Some sort of race condition with the `useFlag`. Simpler to just remove
the flag logic entirely and keep the page permanently on.
2026-03-09 12:13:11 -04:00
AnaandAna Mogul 8f71a43b86 chore/www log drains blog post (#43454)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update image for thumbnail

## What is the current behavior?

N/A

## What is the new behavior?

imgThumb has been updated to
`https://zhfonblqamxferhoguzj.supabase.co/functions/v1/generate-og?template=ruler&layout=icon-only&copy=Log+Drains+on+Pro&icon=icon-columns.svg`

## Additional context

Add any other context or screenshots.

---------

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-05 14:12:18 -05:00
Prashant Sridharan 96b2ba71a6 Fixed typos and changed the prize on an event (#43459) 2026-03-05 18:41:27 +00:00
AnaandAna Mogul 604fc7b4c8 blog: add Supabase Storage performance, security, and reliability updates (#43461)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adding a blog post for the Supabase Storage performance, security, and
reliability updates that has been shipped

## What is the current behavior?

N/A

## What is the new behavior?

Adds the blog post "Supabase Storage: major performance, security, and
reliability updates" covering:

- Path traversal prevention
- Accidental SQL delete protection
- Object listing rewrite (up to 14.8x faster deep pagination on 60M+ row
tables)
- Query cancellation and statement timeouts
- Idempotent migrations
- TUS zombie lock fix
- Orphan object scanner improvements
- OpenTelemetry metrics
- Bug fixes

## Additional context

Related PRs: https://github.com/supabase/storage/pull/818,
https://github.com/supabase/storage/pull/817,
https://github.com/supabase/storage/pull/841,
https://github.com/supabase/storage/pull/805,
https://github.com/supabase/storage/pull/812,
https://github.com/supabase/storage/pull/830,
https://github.com/supabase/storage/pull/819,
https://github.com/supabase/storage/pull/831

---------

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-05 13:22:43 -05:00
549ca3677e feat: add similar threads on contribute (#42638)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This adds a component showing a list of AI curated related threads to
the detail thread view.

## What is the current behavior?

This is not available.

## What is the new behavior?

A new component on the thread view.

## Additional context

Add any other context or screenshots.

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-03-05 12:06:55 -05:00
AnaandAna Mogul 1fe188fcb7 Add Log Drains now available on Pro blog post (#43433)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

A new blog post to announce Log Drains being available on Pro

## What is the current behavior?

N/A

## What is the new behavior?

Adds the blog post 2026-03-05-log-drains-now-available-on-pro.mdx
announcing Log Drains availability on the Pro tier. It will be live at
https://supabase.com/blog/log-drains-now-available-on-pro

## Additional context

Related to #43360 (Log Drains feature page update for Pro launch)

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-05 10:08:38 -05:00
AnaandAna Mogul e988996e62 chore(www): update Log Drains feature page for Pro launch (#43360)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update Log Drains feature page

## What is the current behavior?

The Log Drains feature page (`/features/log-drains`) reflects outdated
information:
- Status shows Public Alpha
- Description only mentions Datadog and custom HTTP endpoints
- Docs link points to the original blog post (`/blog/log-drains`)
- No mention of Pro plan availability

## What is the new behavior?

- Status updated to GA
- Description updated to reflect Pro plan availability (previously
Team/Enterprise only)
- All supported destinations listed: Datadog, Grafana Loki, Sentry, AWS
S3, Axiom, and generic HTTP
- Pricing included: $60/drain/project + $0.20/M events + $0.09/GB egress
- Docs link updated to `/docs/guides/telemetry/log-drains`

## Additional context

Add any other context or screenshots.

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-05 10:08:23 -05:00
Prashant Sridharan ef6e44bc24 Fixed a few typos in the text (#43434)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Just clarified that the prize is an iPhone 17 Pro Max and the dinner is
on a Wednesday, not a Tuesday.
2026-03-05 08:05:59 +00:00
Prashant Sridharan cd0e2c9fa9 Added more landing pages for upcoming events (#43412)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added landing pages for contests and giveaways at upcoming conferences.
Also updated the iPhone 17 Pro Max image with a higher quality one with
proper masking.
2026-03-04 23:07:02 +00:00
Mert YEREKAPAN 6c436d5aa3 fix(Nav): update dashboard link to point to sign-up page (#43384)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes

## What kind of change does this PR introduce?

Redirect to the signup page for "Start your project" button

## What is the current behavior?

That button redirects to signin page

## What is the new behavior?

Redirects to signup page

## Additional context

Add any other context or screenshots.
2026-03-04 14:58:14 +01:00
Prashant SridharanandAlan Daniel d2f46ea76b Added Brevo and Hyper case studies (#43316)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added two new case studies:
- Brevo, omnichannel marketing company using Supabase + Dust agents
- Hyper, marketing agents for your company

Includes avatars for quotes and company logos.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-03-04 07:34:22 +00:00
Prashant SridharanandAlan Daniel 57c5c7b808 Add Stripe Sessions go pages (#43343)
## Summary

- Add contest rules legal page (`/go/contest-rules`) with official
sweepstakes rules
- Add executive dinner landing page (`/go/stripe/exec-dinner`) with RSVP
form backed by HubSpot and Customer.io
- Add executive dinner thank-you page
(`/go/stripe/exec-dinner/thank-you`)
- Add Stripe Sessions contest page (`/go/stripe/contest`) for iPhone 17
Pro Max sweepstakes

## Notes

- HubSpot `formGuid` on the exec dinner page needs to be replaced with
the real value before going live
- Customer.io `staticProperties` support is needed to send `event_name`
as a track property (see TODO comment in exec dinner page)
- iPhone image placed at
`public/images/landing-pages/stripe-sessions/iphone17-pro-max.png`

## Test plan

- [ ] Verify all four pages render correctly at their respective slugs
- [ ] Test RSVP form submission on exec dinner page
- [ ] Confirm contest rules page content matches official legal rules
- [ ] Verify iPhone image renders in contest page hero
- [ ] Check mobile responsiveness on all pages

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-03-03 15:42:03 +00:00
AnaandAna Mogul 10c6f64471 feat: byoc early access page (#43315)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds a dedicated landing page for BYOC Early Access

## What is the current behavior?



## What is the new behavior?

Adds /go/byoc-early-access using the _go lead gen page system. The page
includes:
  - Hero section with "Request Early Access" CTA
- Feature grid with the 4 BYOC value props (data residency, custom
infrastructure, cloud cost optimization, managed operations)
- Early access request form with First Name, Last Name, Email, Company
Name, and Supabase Organization Name fields
  - Dual CRM integration: HubSpot and Customer.io

## Additional context

<img width="2477" height="1182" alt="Screenshot 2026-03-02 at 5 00
18 PM"
src="https://github.com/user-attachments/assets/483abc67-465f-49c6-88c1-1f53c3edafef"
/>
<img width="2460" height="1183" alt="Screenshot 2026-03-02 at 5 00
30 PM"
src="https://github.com/user-attachments/assets/de764bcf-2158-44b9-a95a-9d7ace06bf78"
/>

---------

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-03-02 19:06:55 -05:00
Prashant SridharanandAlan Daniel e8d6824285 Added four new solution pages (#43242)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

I added four new solution pages for marketing purposes:
- B2B SaaS
- Healthcare
- FinServ
- Agents

I followed the data model and components of all existing solution pages.

I also altered the mega menu to include a new category.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-03-02 23:28:29 +00:00
Terry Sutton fc06ffc901 Fix contribute table component (#43298)
Updates react-markdown to be compatible with  remark-gfm

Example issue: 
https://supabase.com/contribute/t/860-66969-11493-reddit_post_1rinknm

fixed: 

https://zone-www-dot-com-git-chore-fix-table-component-supabase.vercel.app/contribute/t/860-66969-11493-reddit_post_1rinknm
2026-03-02 13:21:10 -03:30
Ivan Vasilov b03866f023 chore: Bump vulnerable dependencies (#43148)
This pull request primarily updates dependencies across the project to
their latest versions, improving compatibility, security, and
performance. It also modifies configuration files to align with the
current package management setup.

Dependency upgrades (core libraries and tools):
Bumps dependencies to solve the following issues:
- https://github.com/supabase/supabase/security/dependabot/2855
- https://github.com/supabase/supabase/security/dependabot/2844
- https://github.com/supabase/supabase/security/dependabot/2860
- https://github.com/supabase/supabase/security/dependabot/2815
- https://github.com/supabase/supabase/security/dependabot/2774
- https://github.com/supabase/supabase/security/dependabot/2836
- https://github.com/supabase/supabase/security/dependabot/2816
- https://github.com/supabase/supabase/security/dependabot/2778
- https://github.com/supabase/supabase/security/dependabot/2790
- https://github.com/supabase/supabase/security/dependabot/2793

Configuration and lock file updates:

* Changed `.prettierignore` to ignore `pnpm-lock.yaml` instead of
`package-lock.json`, reflecting the switch to pnpm as the package
manager.
* Updated dependency overrides in `pnpm-lock.yaml` for `tar` and
`fast-xml-parser` to ensure consistent versions across the workspace.

These updates collectively ensure the project stays current with its
dependencies, reduces potential vulnerabilities, and improves overall
stability and maintainability.
2026-03-02 17:07:55 +01:00
Raminder Singh e46d1d559e feat: add a Contact Us page (#43263)
New Contact Us page at `/contact-us`:

<img width="1726" height="1045" alt="image"
src="https://github.com/user-attachments/assets/7dfa9226-7067-4d5f-b7f8-bb45597aad8b"
/>

Link in the Company section (see bottom right):

<img width="1051" height="441" alt="image"
src="https://github.com/user-attachments/assets/873e9884-66b7-48e9-b949-950af1e2dcae"
/>
2026-03-01 19:29:19 +00:00
ce980f1724 Modified past webinars and landing page to include YouTube embeds (#43191)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

I modified previous webinars to include the following:
- A YouTube embed of the recording
- New "Watch the Recording" CTA buttons
- New slug for the go page `/vibe-coding-done-right-webinar`

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-25 20:17:00 +00:00
Sean Oliver 75ec7c6e6b feat(growth): re-land first-referrer cookie attribution with fixed middleware matchers (#43153)
## Summary

Re-lands the first-referrer cookie feature from #42768 (reverted in
#43129) with middleware matcher fixes that prevent Studio traffic
interference.

**Tracks:** [GROWTH-651](https://linear.app/supabase/issue/GROWTH-651)

## What changed

New shared module in `packages/common/first-referrer-cookie.ts` that
handles stamping and parsing a first-referrer cookie (referrer, UTMs,
click IDs, landing URL). Each app's middleware calls
`stampFirstReferrerCookie` on the edge response — www and docs are the
primary entry points, Studio is a fallback for direct visits with UTMs.

On the telemetry side, `handlePageTelemetry` now takes an options object
instead of positional args, reads the cookie on initial pageview, and
overrides the referrer if the cookie captured an external source but the
current referrer is internal (i.e., the user navigated cross-app). Also
sends `first_referrer_cookie_present`/`consumed` properties so we can
observe the handoff in PostHog.

The docs middleware matcher was broadened from `/reference/:path*` to
all docs pages so we stamp cookies site-wide, not just on reference
paths.

## Root cause of original revert

Two layers:

1. **Matcher gap**: www middleware ran on `/dashboard/*` traffic in prod
due to Vercel Multi-Zone architecture (www is the gateway for
`supabase.com`, proxying `/dashboard` → Studio, `/docs` → Docs).
Middleware runs *before* rewrites, so www middleware executed on all
proxied traffic.

2. **`_next/data` interception**: The matcher didn't exclude
`_next/data` paths. Client-side navigation in Next.js fetches JSON via
`/_next/data/...` — middleware intercepted these, returned
`NextResponse.next()` with cookie mutations (which processes through the
middleware response pipeline), and this interfered with the JSON
responses, causing full page reloads in the SQL editor.

## How this PR fixes it

| Fix | Detail |
|---|---|
| Exclude `_next/data` | All three matchers (`www`, `docs`, `studio`)
exclude `_next/data` via negative lookahead |
| Exclude `dashboard` + `docs` from www | www middleware no longer runs
on proxied app traffic |
| `/api/` path guard in Studio | Broadened matcher requires explicit
path check for API route filtering |
| `NextResponse.next()` semantics | Cookie stamping only happens on
matched paths; unmatched paths never enter middleware |

### `NextResponse.next()` vs `undefined` nuance

Returning an explicit `NextResponse.next()` with cookie mutations
processes through Next.js's middleware response pipeline (headers are
merged, cookies are set). Returning `undefined` (i.e. the request never
matches the matcher) lets Next.js handle the request completely
untouched. The matcher exclusions ensure `_next/data` and proxied app
paths never enter middleware at all.

## Testing

- ✅ 22 unit tests for shared cookie utilities (all pass)
- ✅ Studio prod build succeeds, middleware recognized as `ƒ Proxy
(Middleware)`
- ✅ Playwright validation: client-side navigation works across 3 page
transitions, `_next/data` requests return 200 OK without middleware
interception, no full-page reloads
- ❌ www/docs SSG builds require platform backend services (expected —
same as master)
2026-02-25 09:24:32 -08:00
AnaandAna Mogul ec332eb387 Add PrivateLink feature page (#42999)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

A new feature page

## What is the current behavior?

N/A

## What is the new behavior?

N/A

## Additional context

Add any other context or screenshots.

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-02-25 11:36:40 -05:00
Alan DanielandJordi Enric 5d409bfd48 fixes for go bolt webginar page (#43180)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.

Co-authored-by: Jordi Enric <37541088+jordienr@users.noreply.github.com>
2026-02-25 16:09:30 +00:00
Prashant SridharanandAlan Daniel b1f93226bb Added video embeds of previous webinars (#43134)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

We are now saving our old webinar videos as unlisted YouTube videos.

I added the video embeds to previous webinars.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-02-24 21:52:32 +00:00
Stephen Morgan e87117a04f chore: update to the AUP (#43114)
Updated AUP based on discussions with Legal and Abuse Ops. 

A lot of wholesale changes based on recent events. Including numbering
in the clauses so these can be directly referred to in communication.
2026-02-25 07:40:17 +13:00