mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
3c305148186c311db7ec03f2e17e91ff94de1200
5446
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
bf5a729f2d |
docs(telemetry): rename section and restructure as Monitoring and Debugging (#48243)
## Summary - Renames the **Telemetry** nav section to **Monitoring and Debugging** (nav label + sidebar title) - Rewrites the section overview (`telemetry.mdx`) as a clean navigation page using `ContentListings` — three panels (Debugging / Monitoring / AI & automation) with no how-to prose - Adds new `telemetry.data.ts` content-listings data file with three groups registered in `index.ts` - Adds a new **Debugging** guide (`debugging.mdx`) — request-stack model, symptom-to-layer router with troubleshooting links for every service, logging guidance - Adds cross-links between `debugging.mdx`, `logs.mdx`, and `advanced-log-filtering.mdx` - Adds a new **AI agents and MCP** page (`ai-agents.mdx`) — MCP tools table, `get_logs` usage, debugging skill workflow - Restructures sidebar into three groups: **Debugging** / **Monitoring** / **AI & automation** ## Motivation - No central entry point existed for debugging — content was scattered across products with no index - The overview page had almost no links for agents to follow - The section name "Telemetry" caused confusion (also used for CLI usage telemetry) - Unblocks the `supabase` debugging skill, which routes agents to this section as its source of truth ## Test plan - [ ] `/docs/guides/telemetry` — three ContentListings panels render, no prose how-to text - [ ] `/docs/guides/telemetry.md` (markdown) — clean link list, navigable by LLMs - [ ] `/docs/guides/telemetry/debugging` — renders correctly, symptom table links resolve - [ ] `/docs/guides/telemetry/ai-agents` — new page renders correctly - [ ] Sidebar shows 3 groups: Debugging / Monitoring / AI & automation - [ ] All cross-links between debugging, logs, and advanced-log-filtering resolve <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary - **New Features** - Added new documentation coverage for AI agent–assisted monitoring and debugging, including an observability-driven troubleshooting workflow. - **Documentation** - Updated the “Telemetry” area to “Monitoring and Debugging” with a refreshed landing page and reorganized sections (Debugging, Monitoring, and AI). - Revised the debugging and logs guides to improve step-by-step guidance and highlight advanced log filtering. - **Navigation** - Renamed and restructured the top-level navigation entry to reflect the new Monitoring and Debugging content layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
6b14df7724 |
chore: Bump vulnerable deps (#48387)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated Next.js, PostCSS, and tar package versions. * Added the required TypeScript native tooling where needed. * Refined package configuration and dependency ordering across the project. * Removed an unused empty dependency configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
76a9ba968c |
refactor(www): unify legal page shells and versioning (#48483)
<!-- ccr-slack-attribution --> _Requested by **Francesco Sansalvadore, Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399057853249?thread_ts=1785399057.853249&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor of the marketing site's legal pages, plus two small content fixes (removal of duplicated dates, two heading corrections) and two permanent redirects. ## What is the current behavior? The documents linked from the Legal Hub are built three different ways: - `/terms` and `/enterprise-terms` render a plain inline heading with no breadcrumbs. - `/sla`, `/support-policy`, `/aup` and `/privacy` are standalone MDX pages carrying their own layout. - `/legal/dpa` has a one-off centered heading and grid of its own. On top of that, the documents that already have a version selector *also* print a "Last Modified" line inside the document body, so the same fact is stated twice on the page. On `/terms` and `/enterprise-terms` the two statements disagree: the selector says "Version 2 — May 6, 2026" while the body says "Last Modified: 1 May 2026". `/privacy` handles its history differently again — earlier versions live at their own archived URLs (`/privacy-260316` and `/privacy-250528`), strung together by "Previous Version" links at the bottom of each page. ## What is the new behavior? Every legal page now renders through one shell: `PageHeader` with a `PageBreadcrumb`, so the Legal Hub is one click away from any document. - The duplicate "Last Modified" rows are removed from the five versioned documents. The version selector is now the single place a date appears. - `/aup` and `/privacy` gain the version selector. - `/privacy`'s three historical versions are now selectable from the one page, and the two old archived URLs permanently redirect to it. - `/sla` and `/support-policy` pick up the shell and breadcrumbs but intentionally show neither a date nor a selector — neither document has ever carried one, and Legal asked that the SLA stay that way for now. Implementation-wise the canonical pattern is the one the Data Processing Addendum page was already using: `DefaultLayout` > `NextSeo` > `PageHeader` (with a `breadcrumb` slot) > `MDXProvider` > `SectionContainer className="prose"` > `LegalDocVersions`. The standalone MDX pages were moved to `apps/www/data/legal/<slug>/vN.mdx` as bare content partials, with a new TSX shell taking over the original route. No route changed except the two archived privacy pages, which redirect. Dates were carried across from the "Last Modified" lines being deleted rather than invented: `/aup` becomes Version 1 — June 1, 2026, and privacy v1/v2/v3 become May 28 2025, March 16 2026 and May 13 2026. ## Additional context **This is a stacked PR.** It is sequenced behind three PRs that touch the same files and should land first: the Terms of Service v3 bump, the Enterprise SaaS Subscription Agreement v3 bump, and #48481 (DPA effective date → August 1, 2026). #48481 edits the very "Last Modified" line this PR removes from the DPA content file, so a trivial conflict there is expected. This branch will be rebased onto master before it leaves draft. **Two contracts now contain a clause that no longer describes the page.** `apps/www/data/legal/terms/v1.mdx` and `v2.mdx` — and the same sentence in the MPPA and both integration-partner addenda — still read "The date on which the Agreement was last modified will be updated at the top of this Agreement". There is no longer a date in the document body; it sits in the version selector above it. Left untouched here because it is contract text, but Legal should re-word it. **The date mismatch is resolved in favour of the selector.** On `/terms` and `/enterprise-terms`, deleting the body line leaves May 6, 2026 as the only date on the page. Nicole Kramer confirmed in Slack that May 6 is the correct date. **Two headings change visibly**, to line up with the labels used on the Legal Hub: "Terms of service" → "Terms of Service", and "Service Level Agreements" → "Service Level Agreement". **`/legal/dpa` now looks almost identical to `/legal/customer-resources/data-processing-addendum`** — same heading, same breadcrumb, different content. The legacy page is a PDF download plus a signing flow and was deliberately left live, but the overlap is more obvious than it was. Redirecting it to the versioned page is the natural follow-up; it is not done here. **Build verification was incomplete in this environment.** `pnpm install` could not finish because `npm.jsr.io` is blocked by network policy (403), so `next build` never gave a real signal. What did run and pass: - `tsc --noEmit` on `apps/www`, with output byte-identical to clean master - ESLint on every changed file — 0 errors - Prettier using the repo's actual config - a direct MDX compile of all 14 `data/legal/**/*.mdx` files using the app's own MDX options The one thing left unverified is webpack resolving `ui-patterns/PrivacySettings` from the privacy content's new directory. CI will confirm that. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8a607a6108 |
feat(www): add Enterprise SaaS Subscription Agreement v3 (#48484)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399555203219)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — a new version of a published legal agreement. ## What is the current behavior? The version selector on `/enterprise-terms` offers two versions of the Enterprise SaaS Subscription Agreement: Version 2 (May 6, 2026) and Version 1 (April 17, 2026). Version 2 is what the page shows by default. ## What is the new behavior? **Before:** opening `/enterprise-terms` showed Version 2 — May 6, 2026. **After:** it shows **Version 3 — August 1, 2026**. Versions 2 and 1 are unchanged and still reachable from the dropdown (`?version=v2`, `?version=v1`). Two files change: - **New** `apps/www/data/legal/enterprise-terms/v3.mdx` — the Version 3 text, transcribed from the source Word document supplied in the Slack thread (`2026.07.29 - Supabase - Enterprise Terms.docx`). - `apps/www/pages/enterprise-terms.tsx` — imports the new MDX and prepends `{ id: 'v3', label: 'Version 3', effectiveDate: 'August 1, 2026', Component: V3 }` to the `versions` array. Since the array is newest-first, v3 becomes the default. ## Additional context ### Transcription fidelity The legal text was not edited, reworded, reordered, or corrected — only re-rendered in the MDX conventions already used by `v1.mdx` and `v2.mdx`. This was verified mechanically rather than by eye: markdown markup was stripped from `v3.mdx` and the result diffed paragraph-by-paragraph against text extracted directly from the source document's OOXML. - **137 paragraphs in the source, 137 in `v3.mdx`, 0 differing.** - 14 top-level sections and 48 subsections, matching the source's heading counts exactly. - All 3 distinct URLs preserved, written as bare URLs per the existing convention in this file family (remark-gfm autolinks them). - Pure ASCII apart from 5 `§` characters in the 48 C.F.R. citations, matching `v1.mdx`/`v2.mdx`. - Prettier clean; no British spellings that would trip the US-locale misspell check. Formatting decisions worth knowing: the source document contains no bold or italic runs at all, but `v1.mdx` and `v2.mdx` both bold defined terms and section numbers, so v3 follows that house style for consistent rendering across the three versions. The source also carries no date or version line of its own; the `_Last Modified: 1 August 2026_` first line is repo convention, matching how every other legal MDX in `apps/www/data/legal/` is written. ### What changed from v2, in the legal text Structure is identical — same 14 sections, same 48 subsection titles. Five substantive prose changes: 1. **Preamble** — the effective date is now "the date of last signature of an Order referencing these terms", replacing v2's unfilled `[Deal.CloseDate]` merge-field placeholder. "Signature block below" becomes "signature block in an Order". 2. **New § 1.4 "Data Processing Addendum"** — defined by reference to `https://supabase.com/legal/customer-resources/data-processing-addendum`, with a carve-out for a separately executed agreement covering the same subject matter. Former § 1.4–1.12 shift to § 1.5–1.13; nothing was removed or reordered. 3. **§ 7.2 Data Processing** replaced — v2's GDPR / UK GDPR / Swiss clause is gone, replaced by a general compliance paragraph that incorporates the Data Processing Addendum into the Agreement. 4. **§ 13.3** cross-reference corrected from Section 10.1 (Mutual) to Section 10.3 (Limited Warranty), which is the clause the refund remedy actually depends on. 5. **§ 14.4 Amendment and Modification** rewritten — v2 required a writing executed by both Parties; v3 gives Supabase a unilateral right to modify by posting a revised version at `https://supabase.com/enterprise-terms`, effective the first day of the following calendar month, or at the start of the next Renewal Subscription Period for Orders with a fixed Subscription Period of 12 months or longer, with non-renewal under § 13.1 as Customer's sole and exclusive remedy. Two things carried over verbatim from the source rather than fixed, since the text must not be edited: § 7.2 is now near-duplicative of § 7.1 (three of its four sentences repeat § 7.1 almost word for word), and "HIPAA" is used in both § 7.1 and § 7.2 without being defined. One pre-existing inconsistency, unrelated to this change: `v2.mdx`'s own first line reads `_Last Modified: 1 May 2026_` while the page lists Version 2's effective date as `May 6, 2026`. Left alone here. ### Overlap with concurrent work Two sibling changes are in flight for the same requester today — one adjusting the new Data Processing Addendum page's dates, one publishing Terms of Service v3. Neither touches these two files, but all three touch the `apps/www/data/legal/` tree, and note that § 1.4 above now links to the DPA page. [#48483](https://github.com/supabase/supabase/pull/48483) removes the `_Last Modified:` first line from every versioned legal MDX, on the principle that the version selector should be the only place a date appears. It is sequenced to land after this PR, and its file list predates `v3.mdx`. A three-way merge of the two branches is clean, but whoever rebases #48483 should add `apps/www/data/legal/enterprise-terms/v3.mdx` to that removal — otherwise v3 keeps a body date after v1 and v2 lose theirs. The `_Last Modified: 1 May 2026` / `May 6, 2026` mismatch on v2 is also handled in #48483 and is deliberately left alone here, so the same line isn't touched by two PRs. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
44bc7b5a57 |
feat(www): add Terms of Service v3 (effective August 1, 2026) (#48482)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399344523739)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — adds a new version of the Terms of Service to the marketing site (`apps/www`). ## What is the current behavior? `/terms` offers two versions in the version dropdown: **Version 2 (May 6, 2026)**, shown by default, and **Version 1 (July 11, 2025)**. ## What is the new behavior? `/terms` shows **Version 3 (August 1, 2026)** by default. Version 2 and Version 1 are still selectable from the version dropdown (`/terms?version=v2`, `/terms?version=v1`) and are completely unchanged. Two files: - **New:** `apps/www/data/legal/terms/v3.mdx` — the full v3 Terms of Service. - **Changed:** `apps/www/pages/terms.tsx` — imports `V3` and prepends it to the `versions` array. Newest-first ordering is required, because `LegalDocVersions` treats `versions[0]` as the latest. ## Additional context ### The legal text is a verbatim transcription — please review it as such It comes from a Word document supplied by Legal, converted with pandoc and then verified character-exact against the source: **8055 words, 136 blocks, 0 word-level diffs**. Prettier was run over the file and changed nothing. **Known typos in the source document were deliberately preserved. Please do not correct them in review:** - §1 Definitions contains a **duplicate `d.`** — one `d.` introduces the Data Processing Addendum definition and the very next item is also lettered `d.` for the Documentation definition. The list therefore runs a, b, c, d, d, e … Re-lettering would shift internal cross-references, so it is left exactly as drafted. - §12(d) Survival contains a **doubled “and”** — *and Sections 1, 5, 6, 8, 9, 10, 11, and 13, and 14 survive*. Also preserved verbatim from the source: curly quotes on the Data Processing Addendum definition only (every other defined term uses straight quotes), and non-breaking spaces around the hyperlinks. ### Date The source document carries **no date line of its own**, even though its §14(d) states that the last-modified date *will be updated at the top of this Agreement*. August 1, 2026 was specified by the requester, and is placed in the `_Last Modified: 1 August 2026_` line at the top of the MDX, following the v1/v2 convention. As with v1 and v2, the `.mdx` uses `D Month YYYY` while `effectiveDate` in `terms.tsx` uses US long form (`August 1, 2026`). That split is pre-existing and intentional. ### New DPA link §1 of v3 links the Data Processing Addendum page at `/legal/customer-resources/data-processing-addendum`. This link is new relative to v2, and the DPA is also incorporated by reference in §7(b). ### No overlap with the concurrent DPA branch This PR touches only `apps/www/data/legal/terms/v3.mdx` and `apps/www/pages/terms.tsx` — **zero file overlap** with the branch updating the DPA page dates. ### Reviewer checklist - 14 numbered sections (1 Definitions → 14 Miscellaneous), 44 lettered subsections, 6 roman sub-subsections. - ALL-CAPS acceptance block at the top; ALL-CAPS AI disclaimer at the end of §9(b); ALL-CAPS §11 Limitations of Liability. - Three link targets intact: the DPA page, `https://supabase.com/privacy`, and `mailto:legal@supabase.io` (×3). Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4db78dfe5f |
chore(www): update DPA effective date to August 1, 2026 (#48481)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399057853249?thread_ts=1785399057.853249&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — moves the Data Processing Addendum's effective date out by two months. ## What is the current behavior? The DPA page at `/legal/customer-resources/data-processing-addendum` shows "Version 1 — June 1, 2026" in the version selector, and the document body opens with "Last Modified: 1 June 2026". ## What is the new behavior? Both now read August 1, 2026: the version selector shows "Version 1 — August 1, 2026" and the document opens with "Last Modified: 1 August 2026". ## Additional context The page renders a hardcoded `versions` array through the shared `LegalDocVersions` component, so the effective date lives in the TSX file; the "Last Modified" line is simply the first line of the MDX content file. Both were updated, each keeping its file's existing date format (`M D, YYYY` in the TSX, `D Month YYYY` in the MDX). No other content changed. ### Not changed — flagging for confirmation The same June 1, 2026 date appears on a few other surfaces. I left them alone because they are either different documents or point at a dated PDF asset that would need to be re-generated and re-uploaded. Let me know if any of these should move too: - `apps/www/pages/legal/dpa.tsx` — the legacy `/legal/dpa` page, which links `Supabase+DPA+260601.pdf` - `apps/studio/components/interfaces/Organization/Documents/DPA.tsx` — Studio links that same PDF - `apps/www/pages/legal/customer-resources/subprocessor-list.tsx` — the subprocessor list (`June-1-2026.pdf` and a "June 1, 2026" label); a separate document - `apps/www/pages/aup.mdx` — the Acceptable Use Policy, "Last Modified: 1 June 2026"; a separate document Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8dc0f93c59 |
feat(www): serve evals frontend at /evals (#48321)
## Changes Proxies `supabase.com/evals` to the [evals](https://github.com/supabase/evals) frontend, following a similar rewrite pattern as `/ui` and `/design-system`. The evals app already serves under an `/evals` base path per supabase/evals#125. The destination is hardcoded rather than an env var because the evals app lives in a separate repo, and there’s not much benefit to a fully local dev flow here, so the target URL is kept the same in every environment. ## Before merge - Disable deployment protection on the evals Vercel project, otherwise `supabase.com/evals` will show a Vercel login page - Wait until closer to Evals announcement target (July 30th) Closes AI-826 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added routing for the `/evals` section and its subpages. * Evals pages now load from the designated hosted destination while preserving URL paths. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
602aa82855 |
docs(www): add column selection to Postgres Changes feature page (#48455)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Updates the `description` copy of the `realtime-postgres-changes` entry in `apps/www/data/features.tsx` - Documents column selection as a key feature - Clarifies that filters can be applied on one or more columns - Removes a stale closing paragraph and normalizes the `Benefits` heading ## What is the current behavior? The Realtime Postgres Changes feature page lists five key features, does not mention column selection, describes filtering without noting multi-column support, and ends with a summary paragraph that is not part of the approved feature copy. ## What is the new behavior? - Key feature 3 reads "Granular filtering: Apply filters on one or more columns to receive only relevant changes." - New key feature 6 reads "Column selection: Opt in to receive only the columns you choose in the event payload, with the primary key always included." - The `## Benefits:` heading is now `## Benefits` - The closing paragraph "Supabase's Realtime Postgres Changes feature provides a powerful tool for creating responsive, real-time applications while leveraging the full capabilities of your Postgres database." is removed ## Additional context - The Realtime team shipped AND filter composition, expanded filter operators, and column selection on 2026-07-02. Docs were updated on 2026-07-06. - This change brings the feature page in line with the Notion Features Page, which is the source of truth for feature page copy. - Filipe Cabaço (Realtime) approved the content. - `blogUrl` is intentionally not added in this PR. It will follow separately once the launch blog post is live. - Scope is limited to the `realtime-postgres-changes` entry. No other feature entries were touched and the file was not reformatted. `prettier --check` passes on the file. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the “Realtime - Postgres changes” feature documentation with clearer wording for granular filtering and row-level security integration. * Added a new bullet explaining column selection, including primary key inclusion. * Improved formatting in the benefits section and removed outdated closing text. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
a4937812b1 |
feat(www): add Sign in with ChatGPT (beta) blog post (#48418)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content: adds a new blog post. ## What is the current behavior? N/A ## What is the new behavior? Adds the blog post announcing Sign in with ChatGPT (beta). - Authors: Cemal Kılıç, Gregor Vand - Categories: `product` · Tags: `auth`, `chatgpt`, `integrations` ## Additional context Pre-flight checks (per CONTRIBUTING.md): - [x] Prettier passes on the changed files - [x] Vercel preview build succeeds for `www` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a blog post announcing the “Sign in with ChatGPT” beta. * Documented signing in to Supabase with ChatGPT and connecting Supabase through ChatGPT and Codex. * Added guidance on consent, account onboarding, access revocation, and getting started. * **Chores** * Updated an author’s displayed role from “Technical Program Manager” to “Product.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0d465e7b5f |
chore(ui): Remove 'tip' from Admonition (#48419)
Closes FE-3966 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem - The admonition uses both 'tip' and 'note', but the visual distinction has long-ago collapsed. - 'Note' is used far more frequently than 'tip' - The two are very similar and it is confusing to know which one to use when they are visually identical ## Solution Collapse 'tip' and 'note' into one by removing all places where there is 'tip' and updating all references to 'tip' into 'note'. **Note:** This PR also resolves new broken links flagged by the E2E docs checker. It may move to another PR since E2Es keep erroring. ### Specific changes See below for an AI-generated list of changes: - **Type system** — removed `'tip'` from `AdmonitionType`, its `TYPE_TO_VARIANT`/`TYPE_LABEL` entries, and the test case in [`packages/ui-patterns/src/Admonition/](packages/ui-patterns/src/Admonition/) - **Remark plugin** — [remarkAdmonition.ts](apps/docs/lib/mdx/plugins/remarkAdmonition.ts) now maps mkdocs `tip` → `note` - **Lint allowlist** — `tip` dropped from `supa-mdx-lint.config.toml` - **Content migration** — all 109 files with `type="tip"` (across `apps/docs`, `apps/www`, `apps/studio`) converted to `type="note"`; zero remaining hits confirmed by repo-wide grep - **Style guide** — `CONTRIBUTING.md` and `contributing/content.mdx` updated to describe 4 admonition types instead of 5 ### Usage before implementation See the usage table that points toward 'note' as being dominant across all apps: Here's the usage table: | Location | `note` | `tip` | |---|---|---| | apps/docs | ~480 | ~143 | | apps/studio | 34 | 6 | | apps/www (blog) | 19 | 3 | | packages/ui-patterns (tests) | 3 | 1 (parametrized) | | design-system / ui-library / packages/ui / packages/common | 0–1 (test fixture only) | 0 | ## Preview links | App | Page | Search text (Ctrl+F) | Verify | |---|---|---|---| | docs | [/docs/guides/ai-tools/byo-mcp](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai-tools/byo-mcp) | official MCP TypeScript SDK | callout's aria-label="Note" | | docs | [/docs/guides/ai-tools/mcp](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai-tools/mcp) | MCP server is available at | callout's aria-label="Note" | | docs | [/docs/guides/ai/python-clients](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai/python-clients) | Click Connect at the top of any project page | callout's aria-label="Note" | | docs | [/docs/guides/auth/audit-logs](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/auth/audit-logs) | Disabling Postgres storage reduces your database storage costs | callout's aria-label="Note" | | docs | [/docs/guides/database/tables](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/database/tables) | access a custom schema through the Supabase Data API | callout's aria-label="Note" | | docs | [/docs/guides/troubleshooting/edge-function-404-error-response](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/troubleshooting/edge-function-404-error-response) | Always configure an appropriate time frame | callout's aria-label="Note" (was single-quoted type='tip') | | www | [blog: cli-v2-config-as-code](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/cli-v2-config-as-code) | Detecting config drift | callout's aria-label="Note" | | www | [blog: cli-v2-config-as-code](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/cli-v2-config-as-code) | Setting Edge Function secrets | callout's aria-label="Note" | | www | [blog: nosql-mongodb-compatibility-with-ferretdb-and-flydotio](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/nosql-mongodb-compatibility-with-ferretdb-and-flydotio) | If your network supports IPv6 connections | callout's aria-label="Note" | Note: the `www` rows use the `zone-www-dot-com` preview host, not the `docs` one you gave — since blog pages are served from the www app, not docs. ## Manual testing 1. Open preview links for affected pages. 2. Inspect. Open console. 3. Paste the following in and see there is no 'Tip' on the page: ``` document.querySelectorAll('[role="alert"]').forEach(el => console.log(el.getAttribute('aria-label'), el.textContent.slice(0,60))) ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Standardized informational callouts across docs and tutorials from **“Tip”** to **“Note”**, updating multiple examples and guidance blocks. * Updated a few related doc references/links and conditional “Next steps” content. * **UI Updates** * Switched various in-app banners and notices to the **“Note”** style variant. * **Bug Fixes / Improvements** * Removed support for the retired **“Tip”** callout type and aligned docs linting, component behavior, and aria labeling to the remaining admonition types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
37dded67d1 |
feat: unify SkipToContent across studio, docs, www, and design-system (#48314)
## What kind of change does this PR introduce? Feature / a11y polish ## What is the current behavior? Studio and Docs each had their own skip-to-content link (different styling and behaviour). www and design-system had none. ## What is the new behavior? Shared `SkipToContent` in `ui-patterns`, adopted by Studio, Docs, www, and design-system. Documented as a fragment with a short note under Accessibility → Jumping ahead. Tab once to reveal the button (top-left), Enter to jump to a content-only `<main>`. | After | | --- | | <img width="836" height="324" alt="CleanShot 2026-07-24 at 14 08 47@2x" src="https://github.com/user-attachments/assets/6df29452-e53a-4eca-8f64-946f2b9f605d" /> | ## To test Shared steps for every app: enable Tab key navigation if needed, load the preview, press **Tab** once — skip button should slide in top-left. Press **Enter** — focus jumps to main content (no blue ring on `<main>`). Press **Tab** again — first interactive control in the page body, not the sidebar/nav. Hover the skip button — solid fill, clear hover state, no chrome showing through. - **Studio** — [preview](https://studio-staging-git-dnywh-featskip-to-content-supabase.vercel.app) → sign in → any project page - **Docs** — [preview](https://docs-git-dnywh-featskip-to-content-supabase.vercel.app) → any docs page with sidebar - **www** — [preview](https://zone-www-dot-com-git-dnywh-featskip-to-content-supabase.vercel.app) → homepage or any marketing page with the default nav - **Design system** — [preview](https://design-system-git-dnywh-featskip-to-content-supabase.vercel.app) → any docs page (confirm Tab from content does **not** walk the sidebar), plus [Skip to Content fragment](https://design-system-git-dnywh-featskip-to-content-supabase.vercel.app/docs/fragments/skip-to-content) ## Additional context Follow-up to #47694 / #48303 (Studio) and #47515 (Docs). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a reusable “Skip to content” accessibility link across key layouts and pages. - Updated main landmarks to support keyboard focus and skip-link navigation (`id="main"`). - **Accessibility** - Skip links now follow consistent landmark-target conventions and remain hidden until focused. - Improved documentation for skip links/jump shortcuts in persistent chrome layouts. - **Documentation** - Added a dedicated Skip to Content fragment, navigation entry, and expanded accessibility guidance. - Updated button description wording in component docs. - **Tests** - Added component tests for SkipToContent. - **Chores** - Exposed SkipToContent via additional public package entry points. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ca2b50a0a7 |
chore(ui-patterns): collapse the admonition shim into ui-patterns/Admonition (#48377)
Follow-up to #48344: collapses the two resolution paths for the Admonition module into one. `src/admonition.tsx` was a back-compat shim re-exporting `src/Admonition/`. Two ways to resolve one module is exactly what produced the macOS self-import bug fixed in #48344, and the local typecheck errors that #48374 worked around. This removes the shim and standardizes on the PascalCase subpath, matching every other export in the package. **Changed:** - Codemodded all 246 `ui-patterns/admonition` imports to `ui-patterns/Admonition` (240 `.tsx`, 5 `.mdx`, 1 `.ts` across studio, docs, www, design-system, and lite-studio) - Pointed the 5 internal `'../admonition'` imports back at the `'../Admonition'` directory **Removed:** - `packages/ui-patterns/src/admonition.tsx`, and its `./admonition` entry in the exports map (regenerated with `pnpm gen:exports`) ## To test - `grep -r "ui-patterns/admonition" --include='*.ts*'` → no hits - `pnpm test:case-hazards` → passes - `pnpm typecheck` → all 15 tasks green - `pnpm --filter studio run lint:ratchet` → passes - `pnpm --filter ui-patterns vitest run src/Admonition` → 11 tests pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Standardized Admonition component imports across the application and documentation. * Improved compatibility with case-sensitive environments by using the canonical component path. * Removed the legacy Admonition import entry point. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
35b2e82852 |
feat(www): add Data Processing Addendum legal page (#48269)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1784836047880599?thread_ts=1784836047.880599&cid=C0161K73J1J)_ ## What kind of change does this PR introduce? Feature — a new marketing-site legal page. ## What is the current behavior? There is no Data Processing Addendum page under Customer Legal Resources. The only DPA content is a legacy `/legal/dpa` page that links out to a static PDF. ## What is the new behavior? **Before:** no DPA page under Customer Legal Resources; DPA content lived only on the legacy `/legal/dpa` page (static PDF link). **After:** a new DPA page at `/legal/customer-resources/data-processing-addendum`, styled like the Terms of Service page — a version dropdown ready for future versions, a "Last Modified: 1 June 2026" line, and the full DPA text (14 clauses + 3 schedules). A "Data Processing Addendum" link is added to the Legal Hub under Customer Legal Resources, using the same FileText icon as Terms of Service. **How:** - New versioned MDX at `apps/www/data/legal/customer-resources/data-processing-addendum/v1.mdx`. - New page `apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`, modeled on the ToS / integration-partner-addendum pattern and rendering via the shared `LegalDocVersions` component (`versions` entry: `{ id: 'v1', label: 'Version 1', effectiveDate: 'June 1, 2026' }`). - Legal Hub link added in `apps/www/pages/legal/index.tsx` with `type: 'document'`. ## Preview Please review on the Vercel preview deploy. Two URLs to check: - `/legal/customer-resources/data-processing-addendum` - `/legal` ## Notes for reviewers - Content was converted faithfully from the provided .docx (normalized word-content diff: 5678/5678 words, zero missing/extra). The source has no tables. - The legacy `/legal/dpa` page (static PDF link) is left untouched — flag if it should be redirected to the new route or retired. - Typecheck/lint could not be run in the build sandbox due to an unrelated JSR-registry 403 during `pnpm install`; Prettier was run and passes. Please confirm CI (typecheck + lint) is green. ## Additional context Version dropdown is single-version for now and is set up to accept future DPA versions. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- _Generated by [Claude Code](https://claude.ai/code/session_01JA6SATQGc9J8kApnH2NvCz)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
a72259b3f0 |
feat(www): group careers page jobs by department (#48358)
<!-- ccr-slack-attribution --> _Requested by **Dasha Nikolov, Ivan Vasilov** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785158372513869?thread_ts=1785158372.513869&cid=C0161K73J1J)_ **Before:** the careers page lists open roles under one heading per individual team (Auth, Data API, Functions, Realtime, Storage, ...). **After:** roles are grouped under their top-level department heading (Engineering, Design, ...), collapsing the per-team split. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / enhancement to the marketing site (`apps/www`) careers page. ## What is the current behavior? Open positions on the careers page are grouped by individual team, producing one `<h3>` heading per team (Auth, Data API, Functions, Realtime, Storage, ...). This fragments the list into many small groups. ## What is the new behavior? Roles are grouped under their top-level department heading (Engineering, Design, ...), so related teams are collapsed under a single department section. **How:** added a `department: string` field to `JobItemProps` and group on `job.department` (from the Ashby public job-board API, which returns both `department` and `team` as top-level strings per posting) instead of `job.team`. `groupJobsByTeam` is replaced by `groupJobsByDepartment` (it had no other callers), `getServerSideProps` now calls it, and the render loop was updated to key on and display the department heading. All styling, keys, and job rendering are unchanged. ## Additional context A Vercel preview deploy will show the result on the careers page. --- _Generated by [Claude Code](https://claude.ai/code/session_01GEvKydFSLsHhpBbNJ2PEzg)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
6f8fe470a6 | ref(pipelines): Update pricing descriptions given new egress calculation (#48241) | ||
|
|
9113c2ba04 |
feat: markdown alternate tags + llms.txt cleanup (#48287)
The June/July marketing redesign (#47271, #47228) rebuilt the homepage and product pages off the Pages Router, silently dropping their `<link rel="alternate" type="text/markdown">` head tags, and llms-full.txt has been accidentally embedding every blog/customer/event page via an `MD_CONTENT` spread. I restored the tags behind a shared helper, added a CI drift test so a future redesign can't drop them silently again, and trimmed both llms files to the agreed docs-index shape. **Changed:** - **Markdown siblings advertised again**: homepage, the 5 product pages, pricing, and blog emit absolute `.md` alternate URLs via a new `mdAlternates(slug)` helper (the one documented consumer of the tag parses it from `<head>` and fetches the `.md` sibling, so tags must point at the sibling, never the page itself). - **Drift test**: a vitest file walks `content/md/**` and asserts every markdown-served slug's page wires the helper (or is covered by the Pages Router `_app.tsx` mechanism, whose alternate-link wiring the test also asserts directly so removing it fails CI too). Source-level assertions by design: page modules can't be imported under www's vitest config. Fails correctly when wiring is removed (verified by hiding a page and by altering the `_app.tsx` tag). - **Vector orphan fixed**: `content/md/vector.md` moved to `modules/vector` matching the live route (the page previously had no negotiation or tag, and `/modules/vector.md` 404'd); `/vector.md` now 308s to `/modules/vector.md` and the legacy `/llms/vector.txt` redirect no longer chains. - **llms.txt + llms-full.txt**: the `## Product Overview` sections are gone from both, each keeps a `## Pricing` section. This deletes the hand-maintained links array (a drift trap) and fixes the accidental ~470-page embed, shrinking llms-full.txt from ~9.8MB to ~4.9MB and dropping the 4.1MB generated content module from that route's serverless bundle. **Note:** this PR is scoped to apps/www only. The docs side (troubleshooting pages and the rest of the docs surface) is handled separately through a consolidated manifest-gated mechanism; an earlier troubleshooting-tag commit was reverted out of this branch to keep the scopes clean. <details> <summary>Why alternate tags matter (background)</summary> Agents ingest markdown far more efficiently than our rendered HTML: a fraction of the tokens and no extraction step. Since #47770 removed UA-based serving (UA sniffing broke a major AI app's fetcher and poisoned CDN caches), markdown is served only on explicit request: a `.md` suffix URL, an `Accept: text/markdown` header, or llms.txt. That's the right serving model, but it makes the markdown twin invisible to any agent that doesn't already know our URL convention, and the major AI fetchers send browser/wildcard Accept headers, so bare URLs hand them HTML. The `<link rel="alternate" type="text/markdown">` head tag is the standards-based advertisement of the sibling. It has a documented consumer today: an agent CLI that parses the tag from `<head>` and then fetches the `.md` sibling, which is also why the tag must point at a real sibling URL and never at the page itself. Peer docs sites ship this tag as table stakes. These www pages used to carry it until the June/July marketing redesign silently dropped it; the drift test in this PR turns that regression class into a CI failure. </details> ## To test Tested locally (www + docs dev servers): - [x] `/llms.txt` renders `## Documentation` + single-link `## Pricing`, no Product Overview - [x] `/llms-full.txt` renders `# Supabase` → `## Pricing` → `## Documentation`, no Product Overview, ~4.9MB - [x] Full www suite: 6 files / 71 tests green; drift test fails correctly when a page is removed or the `_app.tsx` wiring is altered - [x] `generateMdContent.mjs` emits `modules/vector`, bare `vector` slug gone On the Vercel preview (browser-verified with Playwright): - [x] Alternate tag present on `/`, `/auth`, `/database`, `/storage`, `/edge-functions`, `/realtime`, `/pricing`, and a blog post: exactly one tag each, href = preview origin + `.md` sibling - [x] `/vector.md` → 308 → `/modules/vector.md`, renders as markdown (`# Supabase Vector`) - [x] `/llms.txt` shows single-link `## Pricing`, no Product Overview - [x] Coverage sweep: all 482 `MD_PAGES` slugs + changelog index/entry curled on the preview; 471 pages carry exactly one tag, all `.md` siblings 200 as `text/markdown`. The 11 misses are legacy blog slugs whose HTML 308-redirects away (stale `MD_PAGES` entries predating this PR, no head to tag; follow-up tracked in Linear) Post-merge prod: - [ ] Full llms.txt link sweep (every linked URL 200s; previews can't cover the docs-hosted links) ## Linear - fixes GROWTH-1013 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Markdown alternate links across key product, pricing, blog, and troubleshooting pages. * Added Supabase Vector documentation covering features, use cases, workflows, and technical details. * Updated AI-focused documentation indexes with dedicated pricing content. * Added redirects for updated Vector documentation URLs. * **Tests** * Added coverage to verify Markdown documentation links stay aligned with available pages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2f0a582198 |
chore: remove triplit link (#48286)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Blog update ## What is the current behavior? Triplit link goes to triplit.dev which is no longer registered/active ## What is the new behavior? No more triplit.dev link <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the blog post’s opening paragraph by removing the hyperlink from the “Triplit” text. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ddd0f3e8d8 |
feat(www): update Grafana Cloud blog post authors (#48284)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — updates the author byline on an existing blog post (`apps/www`). ## What is the current behavior? The "Observability for every Supabase project with Grafana Cloud" post lists a single author (`raminder_singh`). ## What is the new behavior? Updates the byline to the three authors credited in the source doc: Alex Hall, Matt Linkous, and Raminder Singh. - Adds a new `authors.json` entry for `alex_hall` (GitHub `alexhall`, Engineering) - `matt_linkous` and `raminder_singh` already existed - Updates the post frontmatter: `author: alex_hall, matt_linkous, raminder_singh` ## Additional context - Source doc: [Notion](https://app.notion.com/p/supabase/Blog-Post-Grafana-Cloud-Partner-drop-3455004b775f8108935feefecd87623f) - Follow-up to #47716 (the original post, already merged) - Pre-flight: Prettier passes; `authors.json` is valid JSON <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Grafana Cloud observability blog post to credit all contributing authors. * Added an author profile for Alex Hall, including their role and profile details. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b6e574e5cd |
fix(www): stop on-demand mdx events from winning the events marquee (#48264)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix — the [events index](https://supabase.com/events) was featuring the TRAE webinar in its marquee days after the event happened, instead of the next genuinely upcoming event (the Dublin meetup), and counting it toward the "Webinar" filter chip alongside actually-upcoming webinars. ## What is the current behavior? `getMdxEvents()` in `lib/events.ts` only excludes past events by comparing dates against the start of today in UTC. It doesn't check `onDemand` at all. The TRAE event's timestamp (`2026-07-22T19:00:00.000-07:00`) converts to `2026-07-23T02:00:00Z`, which is still "today or later" by that UTC cutoff — so even though the event already happened and flipped to `onDemand: true`, it kept getting returned as an "upcoming" event. Since the events marquee (`featuredEvent`) just picks the earliest-dated event from that pool, TRAE kept winning over the actually-upcoming Dublin meetup, and it kept counting toward the "Webinar" filter chip. ## What is the new behavior? `getMdxEvents()` now excludes any event with `onDemand: true` outright, regardless of how its date converts across timezones — on-demand events belong solely in the on-demand bucket (`getOnDemandMdxEvents`), not the upcoming/marquee pool. Verified locally: the "Webinar" filter chip count on `/events` drops to 0 with this in place (previously counted TRAE), while the TRAE event's card in the on-demand list still correctly shows its "Webinar" tag and "Supabase Live" line, matching the other on-demand webinars (Perplexity, Datadog) — only its bucket assignment changed, not its labeling. ## Additional context Couldn't verify the marquee itself locally since the Luma events API returns a 500 in local dev (missing credentials, pre-existing/unrelated to this change). Confirmed independently via the production Luma API that the Dublin meetup (`2026-07-28T17:00:00Z`) is genuinely the next chronological event, so it will naturally take over the marquee once this ships — no hardcoding needed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * On-demand events are no longer shown in the upcoming events list. * Upcoming events continue to be filtered by their relevant date, while on-demand event listings remain unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8252b69b6a |
feat(www): convert TRAE webinar page to on-demand (#48225)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — converts the TRAE webinar event page to its on-demand version and adds a small template enhancement to support a custom type label. ## What is the current behavior? The [TRAE webinar page](https://supabase.com/events/supabase-trae-high-quality-apps) is set up as a live, upcoming event: `onDemand: false`, a registration CTA linking out to GoToWebinar, and copy written in the future tense ("What we'll cover"). The shared event page template (`pages/events/[slug].tsx`) always renders the raw `type` frontmatter value (e.g. "WEBINAR") as the label at the top of the page, with no way to override it. ## What is the new behavior? - Flips `onDemand` to `true` and swaps the `main_cta` from the GoToWebinar registration link to a `#recording` anchor labeled "Watch the recording", matching the pattern used for the Bolt and Perplexity webinars once they went on-demand. - Adds a `video-container` iframe placeholder (`id="recording"`) below the intro copy. The `src` is intentionally left empty with a `TODO` comment — neither the Bolt nor Perplexity on-demand pages expose the recording URL in frontmatter, it's a hardcoded YouTube embed URL in the MDX body, so this needs the real embed URL dropped in before merging. - Replaces the "What we'll cover" section with updated "Key Takeaways" copy and a closing line ("We hope you enjoy the recording!"). - Adds an optional `type_label` frontmatter field to the event page template. When set, it renders in place of the raw `type` value at the top of the page; when unset, behavior is unchanged for every other event page. Used here to show "Supabase Live" instead of "WEBINAR". ## Additional context Verified locally in preview: - TRAE event page renders correctly with the new CTA, video placeholder, updated copy, and "SUPABASE LIVE" label. - Other event pages (e.g. `enterprise-innovation-with-bolt`) are unaffected and still show their original type label, confirming the `type_label` change is backward compatible. Still needed before merging: the actual recording embed URL in the iframe `src`. |
||
|
|
312d05af4b |
fix(www): changelog frontmatter (#48249)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Security/bug fix ## What is the current behavior? The changelog entry parser exposes all YAML frontmatter fields parsed by `matter()` directly to the client via Next.js props. This includes private fields like `internal:` (escalation teams, notes) and `reviewers:`, which get serialized into the page's `__NEXT_DATA__` and are visible in View Source even if never rendered. ## What is the new behavior? - Added `PUBLIC_FRONTMATTER_KEYS` constant that explicitly allowlists only the fields safe to expose to the browser - Added `toPublicFrontmatter()` function that filters frontmatter down to the allowlist, dropping `internal:`, `reviewers:`, and any other private keys - Updated `parseChangelogEntryFile()` to apply the allowlist before returning frontmatter to callers - Added comprehensive unit tests covering both the filtering logic and the integration with the parser This uses an allowlist approach rather than a denylist, so new private fields added upstream won't silently leak to clients. ## Additional context The allowlist is kept in sync with `ChangelogEntryFrontmatter` in `changelog-repo.ts` per the code comment. Tests verify that: - Only allowlisted keys are present in the returned frontmatter - Private fields like `internal` and `reviewers` are never exposed - Public fields flow through untouched - Undefined values are omitted from the result https://claude.ai/code/session_017uSmnCLsskFYR7YH8DKGkr <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a shared changelog title renderer that safely displays titles as inline Markdown. * Added plain-text title extraction for consistent headings and SEO metadata. * **Bug Fixes** * Prevented private/internal changelog frontmatter (including reviewer metadata) from being exposed to browser-rendered pages. * Ensured featured and non-featured changelog timelines stay consistent even when some entries fail to serialize. * Improved the changelog detail not-found behavior to revalidate instead of caching 404s indefinitely. * **Tests** * Added coverage for public frontmatter allowlisting, date normalization (`publish_date`/sorting), and `sortDate` consistency across YAML variations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Lukas Bernert <lukas@bernert.at> |
||
|
|
3effea71aa |
feat(www): add Grafana Cloud partner drop blog post (#47716)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Launch blog post - Grafana! ## What is the current behavior? Nonexistent 😆 ## What is the new behavior? Adds the "Observability for every Supabase project with Grafana Cloud" partner drop post, announcing the one-click Grafana Cloud integration. - Post: [`apps/www/_blog/2026-07-23-observability-for-every-supabase-project-with-grafana-cloud.mdx`](https://github.com/supabase/supabase/blob/blog/grafana-cloud-partner-drop/apps/www/_blog/2026-07-23-observability-for-every-supabase-project-with-grafana-cloud.mdx) - Images: `apps/www/public/images/blog/observability-for-every-supabase-project-with-grafana-cloud/` (og + thumb) - Author: `raminder_singh` · Date: 2026-07-23 · Category: product - Includes the YouTube walkthrough embed and UTM-tagged dashboard links <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a blog post announcing one-click Grafana Cloud observability integration for Supabase projects. * Highlights include preconfigured authentication, metric scraping, and dashboards available on all plans, including free. * Documents dashboard portability, Metrics API usage, setup instructions, and upcoming log support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7c20cc574c |
feat(www): new changelog sync (#47880)
## What kind of change does this PR introduce? Sync changelog from private supabase/changelog. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Changelog entries now come from the structured changelog repository. * Added filters for change type, product stage, and self-hosted impact. * Updated badge UI for affected products and change types with filter links. * Changelog detail sidebar now shows lifecycle stage, sunset dates, and self-hosted impact (when available). * **Improvements** * Product category discovery and filtering now use affected products. * Discussion links show only when legacy discussion data is present. * RSS feeds and generated changelog markdown now use the updated metadata. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3121841863 |
[FE-2271] fix: correct stale email confirmation dashboard paths (#48228)
Users were getting AI-generated troubleshooting steps pointing at **Authentication → Settings → Sign up → "Enable email confirmations"** — a dashboard path that no longer exists (FE-2271). The guidance comes from external LLMs trained on stale supabase.com content: two 2022 blog tutorials contain that exact phrasing. The real toggle is **Authentication → Sign In / Providers → User Signups → "Confirm email"**. **Changed:** - Updated the Flutter chat and Angular Trello blog tutorials to point at the current toggle location (and removed screenshots of the old UI) - Repointed the legacy `/project/:ref/auth/settings` redirect from `/auth/users` to `/auth/providers`, so anyone following stale instructions lands on the page that actually has the auth config ## To test - Visit `/project/<ref>/auth/settings` in Studio — it should redirect to `/project/<ref>/auth/providers` (verified locally on both the redirect and the existing `redirects.shared.test.ts` suite) - Check the two blog posts render correctly and the dashboard deep link opens Sign In / Providers <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Updated authentication settings redirects so project settings pages now open the correct sign-in and provider configuration page. - **Documentation** - Updated Flutter and Angular tutorial instructions for disabling email confirmation. - Added current navigation guidance and clarified where to turn off the **Confirm email** option. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
3bca21b3f8 |
chore(a11y): convert leftover focus recipes to focus-ring (#48219)
## What kind of change does this PR introduce? Accessibility cleanup (DEPR-628). ## What is the current behavior? Leftover call sites still use ad-hoc focus recipes (`ring-foreground-muted`, `outline-brand`, Dialog/Sheet `focus:` rings, etc.) instead of the shared utilities from #41575. ## What is the new behavior? Converts those leftovers across `packages/ui`, Studio, www, docs, and design-system to `focus-ring`, preferring `focus-visible`. Keeps documented exceptions (`group-focus-visible`, InputGroup `:has()`). ## To test Tab through controls (keyboard only). Expect a consistent offset ring on `:focus-visible`, not a green/brand/custom stack, and no ring animation. ### www (marketing) Preview: https://zone-www-dot-com-git-danny-depr-628-focus-ring-fbccf9-supabase.vercel.app - Global nav on `/`: Product, Developers, Solutions dropdowns; logo; hamburger + mobile menu - `/features`: view toggles and feature cards - `/company`: card links - `/changelog`: timeline / entry links - `/partners/catalog`: grid/list toggle and partner cards - `/pricing`: compute section expand control - Product / Modules / Solutions sticky navs on product pages (e.g. `/database`, `/storage`) - `/state-of-startups`: TwoOptionToggle if present ### docs Preview: https://docs-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Any guide page: top nav dropdowns and items - Narrow viewport: hamburger, then mobile menu links + close - Guide with PromptPanel / tabs: tab to prompt actions and tab list ### studio (dashboard) Preview: https://studio-staging-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Project home: Connect section tiles; drag-handle focus on sortable sections - Integrations marketplace (`/project/<ref>/integrations`): featured cards, list/grid toggle, list rows - Auth (`/project/<ref>/auth/oauth-apps`, `/project/<ref>/auth/providers`): open create/edit sheet, tab to close (X) - Database policies (`/project/<ref>/database/policies`): open policy editor sheet, tab to close - Storage policies (`/project/<ref>/storage/files/policies`): bucket section links; policy modal close - Query performance (`/project/<ref>/observability/query-performance`): info icon buttons on metrics - Replication pipeline detail (if available): slot lag / status info icons - Support (`/support/new`): attachment add/remove controls - Table editor: spreadsheet import preview checkboxes; row text/JSON editor TwoOptionToggle - Any Dialog/Sheet/toast close (X): ring on keyboard focus only, not mouse click ### design-system Preview: https://design-system-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Colour palette swatches (keyboard focus) - Form patterns sidepanel example: avatar / focusable control in the example ## Additional context - Linear: [DEPR-628](https://linear.app/supabase/issue/DEPR-628) - Follow-ups: form-group CSS (DEPR-629), Storage columns selection (DEPR-630), ESLint rule (DEPR-632) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility & Usability** * Standardized keyboard focus indicators across navigation, dialogs, forms, buttons, toggles, links, and tooltips using a consolidated focus style. * Improved toggle controls to use proper button semantics (instead of clickable text), including `aria-pressed`/disabled handling and better keyboard navigation. * **Visual Updates** * Harmonized hover/focus ring visuals across the design system, Studio, documentation, and marketing pages while preserving existing layout and interaction behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6f6badae51 |
fix(eslint): promote require-explicit-tabindex to error (#48170)
## What kind of change does this PR introduce? Accessibility / lint hardening (Safari keyboard focus). ## What is the current behavior? `supabase/require-explicit-tabindex` is `'warn'`. Studio’s ratchet was at 0 but the rule was still ratcheted; www / docs / design-system still had raw `<button>` / `role="button"` call sites without an explicit `tabIndex`. [DEPR-627](https://linear.app/supabase/issue/DEPR-627) · follow-up to #47984 / #48040 ## What is the new behavior? - Shared config: `'supabase/require-explicit-tabindex': 'error'` - Swept www / docs / design-system (+ Studio test fixtures the ratchet skipped) - Removed the rule from the Studio ratchet + baselines ## To test Prefer **Safari**. This PR only adds explicit `tabIndex` to raw `<button>` / `role="button"` call sites — not links, and not controls that already go through `Button` from `ui`. ### Marketing (`www`) ([staging link](https://zone-www-dot-com-git-danny-depr-627-promote-req-7ae43c-supabase.vercel.app/)) - [x] Homepage frameworks / dashboard feature tabs — Tab through each tab button - [x] Product pages (e.g. `/auth`, `/database`) — section tab switchers - [x] Narrow viewport — open the hamburger; Tab through menu buttons - [x] `/partners/catalog` — filter / view controls - [x] Blog view toggle (list ↔ grid) ### Docs ([staging link](https://docs-git-danny-depr-627-promote-require-explici-25e46d-supabase.vercel.app/)) - [x] **Desktop (≥ lg):** top-right **⋯ menu** (hamburger icon) — opens a dropdown that includes Theme. Not a separate theme button. - [x] **Mobile (< lg):** top-right **hamburger** opens the sheet; close (X) is the raw button we tagged. Theme inside the sheet uses `ThemeToggle` / `DropdownMenuTrigger` from `ui` (already supposed to set `tabIndex`). - [x] **Code blocks** — copy / language controls - [x] **Is this helpful?** — X / check are `Button` from `ui` (should already Tab). After voting **while signed in**, the follow-up “What went well?” / “How can we improve?” text button is the raw one we tagged. - [x] **AI Tools → Copy as Markdown** (right rail on a guide) — this is the only GuidesSidebar control this PR changed. “On this page” TOC items are **links**, not covered by this lint. - [x] **Reference docs** (e.g. JS client reference) — section headers that expand/collapse in the left nav (`Collapsible.Trigger`) - [x] **Troubleshooting index** — type in the search field, then Tab to the **clear (X)** control ### Dashboard (`studio`) No production UI changes in this PR (tests + lint config only). Quick Safari smoke that prior tabindex work still holds: - [x] Project sidebar — Tab through primary nav links - [x] Settings → General — Tab through inputs / buttons - [x] Storage → Files — Tab a bucket row / file actions |
||
|
|
359974d071 |
fix(docs) Fix local broken links (#48212)
Closes DOCS-1202 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem We have broken local links in docs. I ran locally tests that crawl through all of our docs and flags broken local links. ## Solution This PR fixes local links where they were errored. The report I generated had false-positives, so there are fewer fixes than initially thought. ## Preview checklist Docs preview: https://docs-git-docs-fix-broken-local-links-supabase.vercel.app WWW preview (redirects): https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app | Page | Live (broken) | Preview (fixed) | Where to look | | --- | --- | --- | --- | | Amazon Bedrock | [Live](https://supabase.com/docs/guides/ai/integrations/amazon-bedrock) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/ai/integrations/amazon-bedrock) | **You'll also need** → `A Postgres database with the pgvector extension` | | Getting started | [Live](https://supabase.com/docs/guides/getting-started) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/getting-started) | Tutorial cards → **Expo React Native Social Auth** | | Product security | [Live](https://supabase.com/docs/guides/security/product-security) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/security/product-security) | **Database** list → `Superuser access and unsupported operations` | | OAuth flows | [Live](https://supabase.com/docs/guides/auth/oauth-server/oauth-flows) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/auth/oauth-server/oauth-flows) | End of page, before **Next steps** → `OAuth methods in supabase-js` | | ElevenLabs TTS | [Live](https://supabase.com/docs/guides/functions/examples/elevenlabs-generate-speech-stream) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/functions/examples/elevenlabs-generate-speech-stream) | **Dependencies** → ElevenLabs `JavaScript SDK` | | ElevenLabs STT | [Live](https://supabase.com/docs/guides/functions/examples/elevenlabs-transcribe-speech) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/functions/examples/elevenlabs-transcribe-speech) | **Dependencies** → ElevenLabs `JavaScript SDK` | | Realtime error codes | [Live](https://supabase.com/docs/guides/realtime/error_codes) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/realtime/error_codes) | `RealtimeDisabledForTenant` → reference link | | Expo social auth redirect (legacy) | [Live](https://supabase.com/docs/guides/with-expo-social-auth) | [Preview](https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/with-expo-social-auth) | Should land on the Expo social auth quickstart | | Expo social auth redirect (old tutorials path) | [Live](https://supabase.com/docs/guides/getting-started/tutorials/with-expo-social-auth) | [Preview](https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/getting-started/tutorials/with-expo-social-auth) | Should land on the Expo social auth quickstart | ### Manual testing 1. For each row, open the **Live** link and find the linked text in **Where to look**. 2. Click the link and confirm it 404s or lands on the wrong page. 3. Open the matching **Preview** link, find the same linked text, and click it. 4. Confirm the preview link resolves to the correct destination: - Amazon Bedrock → `/docs/guides/database/extensions/pgvector` - Getting started → `/docs/guides/auth/quickstarts/with-expo-react-native-social-auth` - Product security → `/docs/guides/database/postgres/roles-superuser` - OAuth flows → `/docs/reference/javascript/auth-admin-oauth-server` - ElevenLabs TTS / STT → `https://github.com/elevenlabs/elevenlabs-js` - Realtime error codes → `/docs/guides/troubleshooting/realtime-project-suspended-for-exceeding-quotas` - Redirect rows → `/docs/guides/auth/quickstarts/with-expo-react-native-social-auth` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated links for pgvector, OAuth, ElevenLabs SDK, and database security guidance. * Corrected the Expo React Native social authentication tutorial link. * Updated Realtime troubleshooting references to the current documentation path. * **Bug Fixes** * Fixed redirects for Expo social authentication guides so legacy URLs reach the correct quickstart. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
90a53a5ee2 |
feat(studio): add shadcn tweet to sign-in testimonials (#48204)
## What kind of change does this PR introduce? Chore ## What is the current behavior? Sign-in testimonials are drawn from the weighted tweet pool in `packages/shared-data/tweets.ts`. shadcn's quote is not included. Resolves [FE-3978](https://linear.app/supabase/issue/FE-3978/add-shadcn-tweet-to-sign-in-page). ## What is the new behavior? Adds [@shadcn](https://x.com/shadcn/status/1672913636132790272)'s tweet ("Supabase is really good. ⚡") with weight `10`, plus the profile image under `twitter-profiles`. ## Additional context Weighted selection on the Studio sign-in page and `topTweets` on www both pick this up from the shared list. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated tweet module documentation to explain how tweet `weight` impacts Studio sign-in weighted random selection and the `topTweets` list (top 18 by weight). * **New Content** * Added a new tweet to the collection with an explicit `weight` of 10, making it eligible for weighted selection and top-ranked inclusion. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ffd5a93f37 |
feat(www): add hidden Legal Hub subprocessor list page (draft) (#48100)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1783431374242039?thread_ts=1783431374.242039&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (`apps/www`). ## What is the current behavior? No public page for Supabase's subprocessor list, and no way for customers to be notified when it changes. ## What is the new behavior? A new hidden page at `/legal/customer-resources/subprocessor-list` shows the current dated subprocessor PDF and lets anyone subscribe with their name and email to receive an email whenever the list is updated. The page is `noindex` and not linked from any nav, so it's shareable by direct URL only for now. Mirrors Wiz's sub-processor-list page. **How:** - **Page** `apps/www/pages/legal/customer-resources/subprocessor-list.tsx` — pages-router, mirrors the existing Legal Hub pages (`DefaultLayout`, `NextSeo`, `PageHeader` + breadcrumb, `SectionContainer` prose). Embeds the PDF (inline preview + download link) and renders the subscribe form. Marked `NextSeo` noindex/nofollow and intentionally left unlinked. - A single `CURRENT_PDF` constant (filename + display date) is the only thing to change when Legal hands over a new dated PDF. - **Form** `apps/www/components/SubprocessorUpdatesForm.tsx` — mirrors `SecurityNewsletterForm` (First name, Last name, Email; `ui` primitives). Carries the framing copy verbatim, with **Subscribe to updates** bold and Privacy Policy linked to https://supabase.com/privacy. - **API route** `apps/www/app/api-v2/submit-form-subprocessor-updates/route.tsx` — exact mirror of `submit-form-security-newsletter`; subscribes the user to the Customer.io "Subprocessor Alerts" subscription (topic 4) via `cio_subscription_preferences.topics.topic_4: true`. - **PDF** `apps/www/public/legal/subprocessor-list/June-1-2026.pdf`. **Updating the list in future:** Drop the new dated PDF into `apps/www/public/legal/subprocessor-list/` and update the `CURRENT_PDF` constant. Nothing else changes. ## Additional context **Notes / to confirm:** - Customer.io topic id `4` → `topic_4` (per Prashant); not independently verified against Customer.io. - Draft: page is intentionally unlinked and noindex until Legal signs off. --- _Generated by [Claude Code](https://claude.ai/code/session_01D9WS2QWQ8Y3o7PqDZabS3F)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
1952abb6d1 |
Fix featured blog post layout breaking on mobile with many authors (#48114)
AuthorAvatars now caps visible avatars at 4 (showing a "+N" badge for the rest) and collapses author names to "First Author, +N others" once there are more than two, instead of joining every name into one long string. A tooltip shows the full list. <img width="434" height="306" alt="Screenshot 2026-07-21 at 15 14 38" src="https://github.com/user-attachments/assets/507ce37e-b080-4dd6-bd49-ca694252cd72" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Enhancements** * Blog author displays now cap at three visible avatars and show a “+N” indicator for additional authors. * Author name labels are now summarized for multi-author posts (with full author names available via tooltip when applicable). * Featured post metadata (author, published date, reading time) has improved spacing, truncation behavior, and responsive visibility on smaller screens. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4158293d02 | fix: Fetch federated content on www build (#48145) | ||
|
|
94f2f5a4a3 | feat(pipelines): Adjust blog post naming (#48154) | ||
|
|
6928a0157b |
fix(www): correct Supabase Pipelines public alpha post date to July 21 (#48152)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Updates the publish date of the "Supabase Pipelines is now in Public Alpha" blog post from July 15 to July 21 - Renames the post file to match the new date - Updates the `date` frontmatter field ## What is the current behavior? The post is dated 2026-07-15. ## What is the new behavior? - The post is dated 2026-07-21 to match the public launch date - File renamed to `apps/www/_blog/2026-07-21-supabase-pipelines-public-alpha.mdx` - Frontmatter `date` set to `'2026-07-21'` ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the publication date for the Supabase Pipelines public alpha blog post to July 21, 2026. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
d5c5a95cc8 |
feat(www): add "Supabase Pipelines is now in Public Alpha" blog post (#47864)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Add a new blog post: `apps/www/_blog/2026-07-15-supabase-pipelines-public-alpha.mdx`, announcing that Supabase Pipelines is moving from private to public alpha - Covers new schema change support (add/remove/rename columns, nullability/default changes), a faster parallelized initial copy, and new destination request forms for ClickHouse, Snowflake, and DuckLake - Authored by `riccardo_busetti` ## What is the current behavior? N/A — this is a new blog post page at `/blog/supabase-pipelines-public-alpha`. ## What is the new behavior? - New post published at `/blog/supabase-pipelines-public-alpha` ## Additional context n/a <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **Announcements** - Published a new blog post announcing **Supabase Pipelines** is now available in **Public Alpha**, with updates on improved performance and operability since private alpha. - **Documentation** - Documented **schema change support**, **faster initial copy** via parallelized table copying, and the pipeline lifecycle based on **Postgres logical replication**. - Added details for the first destination (**BigQuery**), destination request forms (ClickHouse/Snowflake/DuckDBLake), plus **roadmap**, **pricing**, **getting started**, and **public-alpha caveats**. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> Co-authored-by: Riccardo Busetti <riccardo.busetti@supabase.io> |
||
|
|
24ce0ba5f8 |
chore: migrate repo to pnpm v11 (#48033)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / dependency tooling update. ## What is the current behavior? The repo is pinned to pnpm 10.24.0. Closes https://linear.app/supabase/issue/FE-3673/migrate-the-repo-to-use-pnpm-v11. ## What is the new behavior? The repo is pinned to pnpm 11.13.1, pnpm v11 workspace settings are migrated to `allowBuilds`, and the Studio Dockerfile installs pnpm 11.13.1. ## Additional context Validated with `CI=true mise exec node@22 -- pnpm install --frozen-lockfile`, `mise exec node@22 -- pnpm run typecheck`, and `mise exec node@22 -- pnpm run lint`; full Prettier check still fails on existing generated docs/router files outside this migration. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated tooling requirements (pnpm **11.13.1**, Node **>=22.13**) and aligned container build tooling accordingly. * Adjusted package manager behavior (scoped registry override, update notifications disabled) and workspace build/engine validation settings. * **Maintenance** * Updated `clean` scripts across apps/packages to remove only build/cache artifacts (no longer delete installed dependencies). * Reduced Turbo `clean` task output to **errors-only** for cleaner logs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74a0848ea5 |
Update logos on homepage (#48087)
Updates logos on homepage and removes slider |
||
|
|
c914163a06 |
Improve features search with relevance-based ranking (#48039)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature enhancement ## What is the current behavior? The features page filters search results by simple substring matching, treating all matches equally. Features are then sorted alphabetically regardless of search relevance. ## What is the new behavior? Search results are now ranked by relevance using a weighted scoring system: - Title matches starting with the search term score highest (5 points) - Title substring matches score 4 points - Subtitle matches score 2 points - Description matches score 1 point Results are sorted by relevance score (highest first), with alphabetical ordering as a tiebreaker. This ensures users see the most relevant features first when searching. ## Additional context The implementation adds: - `SEARCH_WEIGHT` constant defining the relevance weights for different match types - `getSearchScore()` function that calculates a feature's relevance to a search term - Updated filtering and sorting logic that uses relevance scoring The weights are carefully chosen so that any title match always ranks above features that only match in subtitle/description, improving search quality without requiring complex algorithms. https://claude.ai/code/session_01573vYv6WZhrboV14NQSuc4 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved feature search with relevance-based matching. * Search results now prioritize matches in feature titles, especially title prefixes, followed by subtitles and descriptions. * Results are displayed in relevance order for faster discovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f19cb09b43 | feat(pipelines): Update product docs and UI copy (#47997) | ||
|
|
da74f52421 |
chore(www): Unified Logs open beta blog post (#47645)
Draft blog post announcing Unified Logs in open beta. Post: `apps/www/_blog/2026-07-06-unified-logs-open-beta.mdx` ### Before publishing - [ ] Confirm publish date <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Announced the open beta of Unified Logs, including a single unified, searchable log stream across multiple services. * Introduced log-type filtering with counts, shareable filter/search links, live tailing, and a zoomable timeline for log-volume exploration. * Added per-request details showing request progression and an option to view raw JSON, plus support for forwarding logs externally via Log Drains. * **Content Updates** * Added a new author profile entry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Shane <o@shaneermitano.com> Co-authored-by: Ana <30495040+ana1337x@users.noreply.github.com> |
||
|
|
2279c4e69e |
fix(studio,www): repair Join us on Discord buttons (#47711)
## What kind of change does this PR introduce? Bug fix ## What is the current behavior? The "Join us on Discord" buttons are broken in two places: - **Studio support sidebar** (`HelpPanel`): on light mode the button background is not white, so the intended white button with purple icon and text is broken. - **www `/support` page** (shared `secondary` button variant): the text disappears on hover, and the Discord icon is never rendered (always invisible). Both issues occur on light and dark mode. ## What is the new behavior? - **Studio support sidebar**: force a white background on all colour schemes via `bg-white hover:bg-white/90`, matching the existing pattern in `DiscordCTACard`. The purple icon and text now render correctly on light mode. - **Shared `secondary` button variant** (`packages/ui`): - The icon container used `text-border-muted`, which blended into the `bg-foreground` button, so the icon was invisible. Changed to `text-background` to match the button's text colour. - The hover state used `text-border-stronger`, which had no contrast against the background, so text disappeared on hover. Changed to `text-background/80`. - Removed the ineffective `fill="var(--background-default)"` from `IconDiscord` on the `/support` page — the SVG path uses `currentColor`, so the fill prop had no effect. These `secondary` variant fixes apply globally, so other secondary buttons benefit too. | Before | After | | --- | --- | | <img width="868" height="642" alt="CleanShot 2026-07-07 at 15 39 42@2x" src="https://github.com/user-attachments/assets/6897b6ba-311e-43c7-bb5a-7b70017a54cc" /> | <img width="906" height="610" alt="CleanShot 2026-07-07 at 16 21 31@2x" src="https://github.com/user-attachments/assets/16104cf0-8ed1-4857-8467-532c1f7fdb5f" /> | | <img width="636" height="620" alt="CleanShot 2026-07-07 at 15 24 53@2x" src="https://github.com/user-attachments/assets/75f55f6c-eaa7-45ee-94fe-eac513126eff" /> | <img width="656" height="404" alt="CleanShot 2026-07-07 at 16 24 23@2x" src="https://github.com/user-attachments/assets/35649b23-fcdd-42fd-8140-e4aaf394667e" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Style** * Refreshed secondary button styling for a more consistent look, including updated hover and loading text/icon colors. * Improved the “Join us on Discord” button’s background and hover appearance. * Simplified the Discord card’s icon rendering to rely on the default icon styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
805aee289e |
fix(studio): color regressions after theme update (#47794)
## What kind of change does this PR introduce? Bug fix + small shared component ## What is the current behavior? After the recent colour system changes, several UI elements lost contrast in light mode: - `InfoIcon` with a background appeared as a flat grey circle (glyph fill matched the background) - Several buttons forced `text-white`, which no longer contrasts correctly against the updated brand fills - Selected / completed check badges were inconsistent between call sites ## What is the new behavior? - `InfoIcon` uses `text-background` for the glyph fill so the "i" is visible against the grey circle - www primary buttons drop hardcoded `text-white` and use standard `Button` colours - New shared `SuccessCheck` in `ui` for selected state and completion progress (green circle; white check in light mode, black check in dark mode) - Documented in the design system with selected + progress examples Note on `InfoIcon`: [#47933](https://github.com/supabase/supabase/pull/47933) landed a related fix using `text-background-200` (`--card`). This PR keeps `text-background` instead, to match `CheckIcon` / `EyeOffIcon` in the same file and avoid the legacy alias. | Before | After | | --- | --- | | <img width="688" height="268" alt="CleanShot 2026-07-10 at 11 30 25@2x" src="https://github.com/user-attachments/assets/c0276b0c-1023-46c8-805c-35a22def1353" /> | <img width="664" height="278" alt="CleanShot 2026-07-10 at 11 29 43@2x" src="https://github.com/user-attachments/assets/3508cf37-1b48-4fb7-a939-83522feb44f1" /> | | <img width="468" height="550" alt="CleanShot 2026-07-10 at 11 31 04@2x" src="https://github.com/user-attachments/assets/acd42273-15ce-4fb2-9d0c-5a43ac23073c" /> | <img width="460" height="540" alt="CleanShot 2026-07-10 at 11 32 50@2x" src="https://github.com/user-attachments/assets/f66fb4bc-81f7-4df1-95f5-63980c4e8537" /> | ## To test Use the staging preview link from this PR and check the following in **light mode** (and spot-check dark mode): **www** - Visit `/404` — "Head back" button should have readable text (not white-on-green) - Visit `/company` — "Join the team" button in the Team section - Visit a product page with a hero CTA (e.g. `/database`, `/realtime`) — primary "Start for free" button **studio** - Database → Replication → deploy a read replica — footer `InfoIcon` next to the pricing line should show a visible "i" inside the grey circle - `/redeem` — select an org; green `SuccessCheck` should match light/dark contrast (white check / black check) - Settings → API → service role key row — red "secret" tag text should be readable **design system** - `/docs/components/success-check` — demo, selected-state, and progress examples |
||
|
|
932b5dc3b8 |
Remove skills page from ui library (#47947)
<img width="1033" height="861" alt="image" src="https://github.com/user-attachments/assets/54a104df-1db9-4b97-89db-6eec671b3af7" /> Removes the above AI Skills page from our ui library and instead redirects to the more up to date ai skills docs page. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a direct “Install Skills” link to the AI Skills documentation guide. * Added a permanent redirect from the legacy prompts URL to the new AI Skills guide. * **Documentation** * Updated the docs side navigation to list component pages under “Blocks”. * Removed the AI Skills page content and its navigation/search entries. * Removed the AI editor rules documentation/registry entries, so they no longer appear in the generated documentation set. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
13330e6328 |
fix(ui): expandable video preview image (#47964)
## What kind of change does this PR introduce? Restore preview image on ExpandableVideo trigger component. ## What is the current behavior? <img width="1441" height="698" alt="Screenshot 2026-07-15 at 14 08 58" src="https://github.com/user-attachments/assets/bdb1c4be-71a9-4601-b5c9-ab4fc97c48d1" /> <img width="1273" height="701" alt="Screenshot 2026-07-15 at 14 09 05" src="https://github.com/user-attachments/assets/b8026bcc-3d43-4faa-873b-1745b32c166c" /> ## What is the new behavior? <img width="1434" height="678" alt="Screenshot 2026-07-15 at 14 08 53" src="https://github.com/user-attachments/assets/8a3e64d1-5fe7-4ab9-a71b-3de5808d28b9" /> <img width="1160" height="672" alt="Screenshot 2026-07-15 at 14 08 48" src="https://github.com/user-attachments/assets/db598a47-ed8e-435b-b3ef-8ae9e76761a2" /> --- Also fixed a border-b issue on the PartnerCatalogDetail. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added thumbnail previews for partner catalog YouTube videos. - Improved video preview presentation with clearer overlays and stronger image blur. - **Bug Fixes** - Updated image loading support for YouTube thumbnail URLs. - Refined sticky tab header spacing and alignment while scrolling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7cffbcc47f | docs(cli): add local-dev workflow guide and restructure CLI docs (#47932) | ||
|
|
d23f86021a |
feat(www): Partner Catalog update (#46757)
## Info architecture change around "Partners" The www "integrations" now become more partner-driven. `/partners/integrations` -> now Partner Catalog under `/partners/catalog` (old links redirect to new paths) Moved them close together in the nav dropdown and in the footer <img width="494" height="336" alt="Screenshot 2026-07-09 at 11 06 41" src="https://github.com/user-attachments/assets/a875fef0-0ab8-47ca-8756-d658b27c4892" /> <img width="1149" height="665" alt="Screenshot 2026-07-09 at 11 09 48" src="https://github.com/user-attachments/assets/9631bb72-fe25-4fb4-b1af-9f14a37d02e7" /> ## /partners This page remains untouched in this PR, updates to layout, content and intake form are delegated to #47874 ## /partners/catalog Listed in the [catalog](https://zone-www-dot-com-git-feat-www-partners-pages-supabase.vercel.app/partners/catalog) are now partners. Some partners match with a listing. <img width="1207" height="866" alt="Screenshot 2026-07-09 at 11 14 17" src="https://github.com/user-attachments/assets/b65216be-976f-4ef5-91f8-1ad49da87b45" /> ## /partners/catalog/[partner] Each partner can have one or more "listings" which are either - simple guides - foreign data wrappers - dashboard integrations Integrations available in the dashboard now all have a prominent "Install integration" cta to open it in the dashboard [integrations page](https://supabase.com/dashboard/project/_/integrations). <img width="1269" height="776" alt="Screenshot 2026-07-09 at 11 16 51" src="https://github.com/user-attachments/assets/3c7bb715-ffce-4d0a-905f-9a660c3b1f5a" /> ## Docs Update docs → [Preview](https://docs-git-feat-www-partners-pages-supabase.vercel.app/docs/guides/integrations) - remove "Supabase marketplace" - use "Dashboard Integrations and Partner Catalog - update integrations in sidenav to link to updated /partners/catalog/** listings <img width="1520" height="696" alt="Screenshot 2026-07-15 at 12 54 47" src="https://github.com/user-attachments/assets/9f5a2794-4536-4299-97df-9732d3d75b4c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Partner Catalog experience with search, category filters, official-partner toggle, responsive filtering (sidebar + bottom sheet), grid/list views, and featured partners. * Added Partner Catalog detail pages with tabbed listings, MDX-rendered content, image gallery with zoom overlay, and “add/install” actions. * **Improvements** * Updated “Become a Partner” layout and form support for prefilled values and checkbox-group fields (including validation). * Updated navigation/footer/docs and partner tile links to use Partner Catalog routes; expanded redirects from legacy integrations paths. * Added public agent-skills discovery manifest. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alan Daniel <stylesshjs@gmail.com> Co-authored-by: Alex Hall <alex.hall@supabase.io> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
1b1b1ea0e0 |
chore: remove dead telemetry code (#47950)
## Summary Removes two pieces of dead telemetry code found while root-causing the docs pageview re-fire investigation (GROWTH-997, closed with no fix needed). Pure deletion, 30 lines, no behavior change. ## Changes - Delete `apps/www/app/ConsentWrapper.tsx`: an unwired third `PageTelemetry` mount. www already mounts `PageTelemetry` in `pages/_app.tsx` (Pages Router) and `app/providers.tsx` (App Router); nothing imports this wrapper. - Remove the exported `POSTHOG_URL` constant from `apps/studio/lib/constants/index.ts`: zero consumers. The CSP allowlist in `apps/studio/csp.ts` defines and uses its own local `POSTHOG_URL`, which stays. ## Testing Deadness verified before deletion, on current master: - [x] Repo-wide grep for `ConsentWrapper`: only self-references inside the deleted file - [x] Repo-wide grep for `POSTHOG_URL`: remaining references are the `csp.ts` local const only ## Linear - fixes GROWTH-1002 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Removed an obsolete consent-related page wrapper to streamline page behavior. * Updated application configuration handling without changing existing payment or usage settings. * **Refactor** * Simplified internal configuration and page composition while preserving the existing user experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
06aafe4e0a |
Skip fetchAgentSkills for www typecheck GHA (#47907)
### Context Our TS check GHA occasionally runs into GH rate limits because of `fetchAgentSkills` ### Changes involved - Opting to omit `fetchAgentSkills` for typecheck - `generateStaticContent` is needed still afaict - Allow GITHUB_TOKEN to be passed for `generateStaticContent` - And pass that env var from `typecheck.yml` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **Improvements** - Enhanced reliability of GitHub-powered content during site builds. - GitHub API requests now use secure authentication when a token is available, improving consistency and reducing rate-limit risk. - Repository star and agent-skill loading continues to work gracefully without token access. - **Chores** - Streamlined the type-check workflow to use a leaner content build before running TypeScript checks. - Passed the GitHub token through relevant CI task environments to enable authenticated requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
99d064e754 |
fix(www): add missing partner slug redirects (#47901)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Partner slugs were renamed from underscores to hyphens, but the redirect map only got partially updated. #46264 added entries for `refine_dev` and `supabase_wrapper_stripe`. Four others were missed and still hard 404, even though their replacement pages are live: | 404s today | Replacement page (200) | |---|---| | `/partners/integrations/atomic_crm` | `/partners/integrations/atomic-crm` | | `/partners/integrations/sequin_io` | `/partners/integrations/sequin` | | `/partners/integrations/supabase_wrapper_bigquery` | `/partners/integrations/bigquery-wrapper` | | `/partners/integrations/supabase_wrapper_firebase` | `/partners/integrations/firebase-wrapper` | These are the URLs Google has indexed and that external sites link to, so that traffic lands on an error page instead of the partner. Roughly 1.3k pageviews/month. Worth flagging for the reviewer: partner slugs come from the database, not the codebase, so renaming one doesn't force a matching redirect entry and nothing catches it at build time. This will happen again. ## What is the new behavior? Four `permanent: true` redirects added to `apps/www/lib/redirects.js`, matching the two that already exist in the partners block. ## Additional context Found while [digging into a decline in /partners traffic](https://supabase.slack.com/archives/C0161K73J1J/p1783931237132339). This accounts for ~7% of that decline — the rest is happening on healthy, indexed pages and is a separate question. Not included here: a few partner URLs 404 with no replacement page (`getstream_io`, `fezto`, `trevor_io`, `zapp_run`) — those partners look genuinely gone. Pointing them at `/partners/integrations` would hold onto more link equity than a hard 404, but that's a product call rather than a bug fix. Happy to add if people want it. Verified each old URL currently 404s and each destination returns 200. No duplicate `source` entries introduced. Prettier passes. |
||
|
|
20cb05230b |
fix site_title (#47884)
Update www `site_title`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the site title and browser metadata to describe the product as “The Postgres Development Platform.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8f82861627 |
feat(replication): Add new form for early access of replication destination (#47046)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added pre-release pages for Supabase Pipelines’ new destinations, including early-access signup, thank-you confirmation, and related resources. * Added destination options for ClickHouse, Snowflake, and DuckLake. * **Bug Fixes** * Improved form validation for grouped required checkboxes. * Added clearer checkbox labels and descriptions. * Forms now explain which required option groups still need a selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <30495040+ana1337x@users.noreply.github.com> |