Commit Graph
149 Commits
Author SHA1 Message Date
Gildas Garcia 63bedef77f MFA Recovery codes: allow users to download their recovery codes (#50267)
## What kind of change does this PR introduce?

After users have set up a new MFA (first or not), we must:

- check whether recovery codes have already been generated
- if there are none, generate recovery codes and display them, "forcing"
users to copy them
- if already generated, show them how many are still available

> [!NOTE]
> The _Delete my recovery codes_ button in last screenshot only appear
on local and staging environments

## How to test

- On an account that doesn't have recovery codes generated yet and has
an MFA added
- You should see an admonition suggesting to generate the codes

## Screenshots

<img width="729" height="306" alt="image"
src="https://github.com/user-attachments/assets/79ba3870-4ef8-4571-9fd6-36eed20c9c24"
/>

<img width="550" height="356" alt="image"
src="https://github.com/user-attachments/assets/1632611a-996a-470d-b6cd-a4693b0f4602"
/>

<img width="719" height="205" alt="image"
src="https://github.com/user-attachments/assets/73cef611-05cf-4fac-bbd2-243f9b28e48d"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added support for generating, copying, and confirming MFA recovery
codes.
- Added recovery-code status visibility, including remaining and
exhausted codes.
  - Added the ability to delete recovery codes with confirmation.
- Added clear loading, success, and error states for recovery-code
actions.
  - Recovery-code status refreshes after codes are generated or deleted.

- **Bug Fixes**
- Recovery-code notices now remain visible when all codes have been
used.
  - Recovery-code dialogs can now be closed after generation errors.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 11:16:47 +02:00
Ivan VasilovandAli Waseem c60bb37a74 chore: Bump nextjs to non-vulnerable version (#50341)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated the Next.js version used by the application and documentation
sites.
* Aligned workspace tooling with the latest supported Next.js 16.3.5
release and refreshed related platform builds.
  * Updated application and documentation sites to Next.js 15.5.24.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 17:55:02 +02:00
1966209483 chore(deps): upgrade vitest to v5 (#49994)
Upgrades Vitest from 4.1.4 to 5.0.0 across the monorepo, fixes the
handful of things v5 turned into hard errors, and drops the
`vi.clearAllMocks()` boilerplate that v5's `clearMocks` default makes
redundant.

**Changed:**
- `vitest`, `@vitest/ui`, `@vitest/coverage-v8` 4.1.4 → 5.0.0 (catalog)
- `vi.mock` calls that lived inside `beforeAll`/`beforeEach`/test bodies
moved to module scope (v5 throws on nested calls). Affects the Studio
and docs setup files and four Studio tests.
- `detectBrowser` test restores `navigator` via `vi.unstubAllGlobals()`
instead of assigning `global.navigator`, which now reaches jsdom's
getter-only property.
- `RowEditor.utils.test.ts` restores its `JSON.stringify` spy. It used
to leak a throwing mock for the rest of the file, which v5's coverage
provider now trips over. A later test in the same file had been
asserting the leak's side effect (valid JSON reported as invalid) and
now asserts the correct behavior.
- `@testing-library/jest-dom` 6.6 → 7.0.1. Its vitest type augmentation
resolves through a peer now, so it lands on each package's own `vitest`
instead of whichever copy pnpm hoisted. Fixes `toBeInTheDocument` type
errors in dev-tools after the reshuffle.
- `@testing-library/react` 16.0.0 → 16.3.3 for the React 19 peer range.
- `vite: catalog:` added to dev-tools, www, and common. Without it they
resolved a newer vite than the catalog pin, which forked a second vitest
instance in the lockfile. There's now one.
- ai-commands custom matcher types use v5's `Matchers<R, T>` form.
- 110 test files: `vi.clearAllMocks()` removed from
`beforeEach`/`afterEach` hooks, along with hooks that only did that and
the imports they left unused. Calls that also reset/restore mocks are
untouched. Second commit, mechanical.

**Added:**
- `.vitest/` to the root gitignore (v5 writes JSON/JUnit/HTML reporter
output there)

**Removed:**
- `vite-tsconfig-paths` catalog entry and deps. Vitest 5 resolves
tsconfig paths itself.

Release-age note: this sat in draft with a temporary
`minimumReleaseAgeExclude` entry for `vitest` and `@vitest/*` while
5.0.0 was inside the workspace's 3-day `minimumReleaseAge` window. That
window has closed, so the exclusion is gone and nothing bypasses the
release-age gate.

**Perf** (local, medians of 3 runs, same machine):

| Suite | v4.1.4 | v5.0.0 |
|---|---|---|
| studio | 144.1s | 141.7s (-2%) |
| studio `--coverage` | 156.9s | 146.4s (-7%) |
| ui-patterns | 6.27s | 5.07s (-19%) |
| ui `--coverage` | 3.35s | 2.14s (-36%) |
| www | 0.89s | 0.47s (-47%) |

Studio is dominated by jsdom environment setup per file, which v5
doesn't change. `vitest doctor` recommends keeping the current pool
config: the vm pools and `isolate: false` all break tests.

## To test

- `pnpm install --frozen-lockfile` succeeds with no
`minimumReleaseAgeExclude` entry for vitest.
- CI: Studio unit tests, ui, ui-patterns, www, docs, and typecheck/lint
should all be green. The lint ratchet was checked locally: warning
counts on touched Studio files are identical to master.
- `pnpm test:studio` locally passes with coverage (588 files, 6240
tests).
- Open a Studio test that uses `toBeInTheDocument` in your editor and
confirm no type errors on jest-dom matchers, in Studio and in
`packages/dev-tools`.
- Known pre-existing failures unrelated to this PR: one dev-tools test
(`getEventCountBadge` capped pill) fails on master too.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Tests
- Improved test coverage for JSON validation and mobile navigation
behavior.
- Updated test setup, cleanup, environment configuration, and matcher
support across application and shared package suites.
- Removed obsolete coverage for alternate MCP transport selection.

## Chores
- Streamlined TypeScript path resolution and Vitest reporter output
handling.
- Updated testing libraries and Vitest tooling across documentation,
Studio, website, and shared packages.
- Added Vitest reporter output to ignored files.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-10 16:45:54 +08:00
Ivan Vasilov c6cdf4bd53 Migrate off contentlayer2 to Velite (design-system, ui-library, learn) (#48546)
## Summary
- `contentlayer2@0.4.6` is unmaintained and drags in a heavy, stale
dependency graph (esbuild pinned to 0.17–0.20, mdx-bundler, old
`@opentelemetry/core`) that was the recurring source of vuln bumps.
- Migrates all three apps that used it — `design-system`, `ui-library`,
`learn` — to [Velite](https://velite.js.org), preserving the generated
typed `allDocs`/`Doc` collection and the `body.code` + `useMDXComponent`
runtime via a small shared local hook.
- Same MDX pipeline (remark-gfm, remark-code-import, rehype-slug,
rehype-pretty-code w/ Shiki compat + local theme,
rehype-autolink-headings, custom
`__rawString__`/`__src__`/`__event__`/`__style__` visitors) ported 1:1
into each app's `velite.config.js`.
- `learn`'s extra frontmatter fields (`chapterNumber`, `explore`,
`courseHero`) are now backed by real Velite/Zod schema types, so the
`(doc as any)` casts in `get-next-page.ts` / `get-current-chapter.ts` /
the doc page could be dropped.
- `next.config.mjs` no longer wraps with `withContentlayer`; since
Velite has no Next.js webpack-plugin equivalent, each app's `dev` script
now runs `velite dev` and `next dev` in parallel via `npm-run-all`.

Ref:
[FE-3861](https://linear.app/supabase/issue/FE-3861/migrate-off-contentlayer2-learn-ui-library-design-system-to-shed)

## Test plan
- [x] `pnpm build:content` (Velite build) succeeds for all three apps
- [x] `pnpm typecheck` passes for all three apps
- [ ] Manual smoke test of `pnpm dev` for each app in a browser (docs
pages render, TOC, copy-button, code highlighting)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Improved content generation across documentation, learning materials,
and the UI library for more consistent pages.
* Preserved MDX rendering, navigation, table of contents, course
metadata, source previews, and component examples.
* Improved consistency when displaying documentation and interactive
examples.
* Improved application loading by optimizing how interface components
are delivered.
* **Chores**
* Streamlined content compilation and development workflows across the
design system, learning area, and UI library.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-04 15:49:44 +02:00
Jeremias Menichelli 143f141e0f feat: initial kb scaffolding (#49601) 2026-08-31 14:55:04 +00:00
supabase-supabase-autofixer[bot]andmandarini b108c4065c feat: update @supabase/*-js libraries to v2.112.4 (#49474)
This PR updates @supabase/*-js libraries to version 2.112.4.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.112.4
- Updated @supabase/auth-js to 2.112.4
- Updated @supabase/realtime-js to 2.112.4
- Updated @supabase/postgest-js to 2.112.4
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.112.4

## 2.112.4 (2026-08-24)

### 🩹 Fixes

- **auth:** convert stolen-lock AbortError when acquireTimeout is 0
([#2616](https://github.com/supabase/supabase-js/pull/2616))
- **auth:** warn on deprecated lock option and prevent unhandled refresh
rejection ([#2627](https://github.com/supabase/supabase-js/pull/2627))
- **postgrest:** move override fixtures out of generated types, repair
codegen ([#2605](https://github.com/supabase/supabase-js/pull/2605))
- **realtime:** respect custom logger for send() REST fallback warning
([#2612](https://github.com/supabase/supabase-js/pull/2612))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- mmustafasenoglu @mmustafasenoglu

This PR was created automatically.

Co-authored-by: mandarini <6603745+mandarini@users.noreply.github.com>
2026-08-25 15:58:14 +03:00
Joshen Lim b9ad5cede7 Bump monaco to 4.80 rc (#49265)
## Context

Resolves FE-4209

Client crash occurs when re-ordering a QueryCell in the new explorer UI
with the error "InstantiationService has been disposed"

Investigated this with Claude which eluded that it's a bug that's within
the Monaco package which `4.8.0-rc.3` actually patched hence opting to
upgrade the package. Verified that monaco still functions as expected +
re-ordering query cells in the explorer UI no longer crashes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated the Monaco Editor integration to release candidate version
4.8.0-rc.3.
  * No visible end-user functionality changes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 12:26:31 +08:00
e66d8eb094 chore(deps): bump Supabase CLI to ^2.114.0 (speculative: Selfhosted Studio E2E Start supabase flake) (#49198)
<!-- ccr-slack-attribution -->
_Requested by **Ivan Vasilov** · [Slack
thread](https://supabase.slack.com/archives/C063LNYJJKS/p1787058646458219?thread_ts=1787058646.458219&cid=C063LNYJJKS)_

**Before:** the root `package.json` pins the Supabase CLI at `supabase:
^2.76.10`, and `pnpm-lock.yaml` resolves it to `2.76.14`.

**After:** it pins `supabase: ^2.114.0`.

This bumps the Supabase CLI that `pnpm run e2e:setup:cli` and `pnpm run
setup:cli` shell out to, so local dev and the E2E workflows boot the
local stack with a CLI from this month instead of one from ~38 minor
releases ago.

**How:** a one-line version change to the `supabase` devDependency in
the root `package.json`. Nothing else in the repo changes — no workflow,
config, or test changes.

### ⚠️ This PR is incomplete: `pnpm-lock.yaml` still needs regenerating

`pnpm-lock.yaml` is **not** updated in this PR, so `pnpm install
--frozen-lockfile` will fail until someone runs:

```bash
pnpm install --lockfile-only
```

and pushes the result to this branch. The lockfile could not be
regenerated in the environment this PR was authored in: pnpm re-resolves
`apps/studio`'s `"@std/path": "npm:@jsr/std__path@^1.0.8"` on every
install, and `npm.jsr.io` is not reachable from there
(`ERR_PNPM_FETCH_403`). Treat this PR as needing one extra commit before
it can go green.

### Why `^2.114.0` and not `^2.115.0`

`2.115.0` is the current `latest` on npm, but it was published only
hours ago, and `pnpm-workspace.yaml` sets `minimumReleaseAge: 4320` (3
days) with `supabase` not in `minimumReleaseAgeExclude`. Pinning
`2.115.0` today would fail the repo's own supply-chain check. `2.114.0`
(2026-08-12) is the newest release that satisfies that policy.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Dependency bump. **Speculative** — this is an experiment, not a
confirmed fix.

## What is the current behavior?

The `Selfhosted Studio E2E Tests` workflow has been failing on `master`
at the `Start supabase` step. Recent runs:

- https://github.com/supabase/supabase/actions/runs/32092940311
- https://github.com/supabase/supabase/actions/runs/32131961447

In the Slack thread, Ivan Vasilov suggested trying a newer CLI and
Alaister Young endorsed giving it a go.

## What is the new behavior?

The workflow runs `supabase start` with CLI 2.114.0 instead of 2.76.14.

The question this PR is trying to answer is simply **"does a newer CLI
help this flake?"** It is not a diagnosis and not a claimed fix. If CI
still fails at `Start supabase` on this branch, the bump can be kept or
dropped on its own merits and the investigation continues elsewhere.

## Additional context

**Verification status:** none locally. The bump was not exercised
locally — this repo checkout has no `node_modules` (see the lockfile
note above), so `pnpm typecheck`, `pnpm lint`, and `pnpm test:studio`
were not run, and neither was `supabase start`. CI on this PR is the
only signal.

**Call-site compatibility check.** CLI 2.99/2.100 moved to a new
TypeScript shell with a stricter argument parser: command-specific flags
must now come *after* the subcommand. Both call sites in the root
`package.json` already use that order, so no script changes are needed:

```
supabase stop --all --no-backup --workdir ./e2e/studio
supabase start --exclude studio,mailpit --workdir ./e2e/studio
```

**Changelog entries between 2.76.14 and 2.114.0 that touch `supabase
start` or local config.** Listed so reviewers know what changed in the
range — **not** as a claim about what is failing in CI:

- **2.112.0** — `supabase start` no longer hangs when analytics
migrations fail; the analytics container exits and retries instead of
booting against an unmigrated database
([#6093](https://github.com/supabase/cli/pull/6093)).
- **2.112.0** — `supabase start` reuses existing volumes instead of
failing when they already exist
([#6037](https://github.com/supabase/cli/pull/6037)); Kong reloads after
`supabase db reset`
([#6017](https://github.com/supabase/cli/pull/6017)); custom auth email
templates survive `db reset`
([#6065](https://github.com/supabase/cli/pull/6065)); `supabase start`
works on SELinux-enforcing hosts
([#6000](https://github.com/supabase/cli/pull/6000)).
- **2.106.0 — behavior change worth watching.**
`[api].auto_expose_new_tables` now resolves to `false` when unset, and
local start/reset revokes default Data API privileges for newly created
`public` tables, sequences, and functions
([#5524](https://github.com/supabase/cli/pull/5524)). Neither
`supabase/config.toml` nor `e2e/studio/supabase/config.toml` sets this
key, so this default applies. If E2E specs create `public` objects and
then read them through the Data API, they may need explicit `GRANT`s
(the deprecated escape hatch is `auto_expose_new_tables = true`).
- **2.106.0** — when the CLI detects a coding-agent environment, or
`--agent yes` is passed, commands default to JSON output
([#5532](https://github.com/supabase/cli/pull/5532)). `e2e:setup:cli`
already passes `--output json` to `supabase status` explicitly, so this
should be a no-op here.
- **2.100.0** — stricter flag ordering, covered above.
- **2.112.0** — `functions deploy` no longer forwards `NPM_AUTH_TOKEN`
into Docker bundling
([#6005](https://github.com/supabase/cli/pull/6005)). Not used by these
workflows.
- **2.107.0** — pg-delta is the default schema diff engine for `db diff`
/ `db pull` on new projects
([#5511](https://github.com/supabase/cli/pull/5511)).
- Many bundled Docker image bumps across the range (`supabase/postgres`
17.6.1.087 → later patches, `postgres-meta`, `vector` 0.28.1 → 0.53.0,
Studio image), plus `fix(analytics): wait for logflare before starting
vector` (2.84.3) and `fix: use correct docker.sock binding with vector`
(2.84.7).

Full comparison:
https://github.com/supabase/cli/compare/v2.76.14...v2.114.0


---
_Generated by [Claude
Code](https://claude.ai/code/session_0143DrDMGnSSwuHebTPJv7ZY)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-08-19 10:52:25 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] a6a12c40a9 feat: update @supabase/*-js libraries to v2.112.3 (#48928)
This PR updates @supabase/*-js libraries to version 2.112.3.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.112.3
- Updated @supabase/auth-js to 2.112.3
- Updated @supabase/realtime-js to 2.112.3
- Updated @supabase/postgest-js to 2.112.3
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.112.3

## 2.112.3 (2026-08-11)

### 🩹 Fixes

- **supabase:** add trace context headers to canonical CORS allow-list
([#2603](https://github.com/supabase/supabase-js/pull/2603))
- **supabase:** improve trace propagation sampling and diagnostics
([#2604](https://github.com/supabase/supabase-js/pull/2604))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.112.2

## 2.112.2 (2026-08-06)

### 🩹 Fixes

- **realtime:** prevent duplicate on bindings
([#2594](https://github.com/supabase/supabase-js/pull/2594))
- **realtime:** clear stale join payload on sign-out
([#2597](https://github.com/supabase/supabase-js/pull/2597))

### ❤️ Thank You

- Filipe Cabaço @filipecabaco
- Vaibhav @7ttp
## v2.112.1

## 2.112.1 (2026-08-05)

### 🩹 Fixes

- **auth:** preserve 5xx error message
([#2587](https://github.com/supabase/supabase-js/pull/2587))
- **realtime:** ensure setAuth doesn't disable token refresh
([#2592](https://github.com/supabase/supabase-js/pull/2592))

### ❤️ Thank You

- Eduardo Gurgel
- Vaibhav @7ttp
## v2.112.0

## 2.112.0 (2026-08-03)

### 🚀 Features

- **supabase:** move OpenTelemetry tracing to opt-in /tracing subpath
([#2583](https://github.com/supabase/supabase-js/pull/2583))

### 🩹 Fixes

- **auth:** accept uppercase UUIDs in validateUUID
([#2467](https://github.com/supabase/supabase-js/pull/2467))
- **postgrest:** honour throwOnError when maybeSingle finds multiple
rows ([#2580](https://github.com/supabase/supabase-js/pull/2580))
- **storage:** resolve createSignedUrls return type mismatch
([#2474](https://github.com/supabase/supabase-js/pull/2474))
- **storage:** expose service error code on StorageApiError
([#2537](https://github.com/supabase/supabase-js/pull/2537))
- **supabase:** forward db retry option
([#2571](https://github.com/supabase/supabase-js/pull/2571))

### ❤️ Thank You

- Anubhav Anand @i-anubhav-anand
- Gourab Singha @gourabsingha1
- Juhef @juheff
- Katerina Skroumpelou @mandarini
- Thribhuvan
- Vaibhav @7ttp
- Zuhef Ahmed @Zuhef
## v2.111.0

## 2.111.0 (2026-07-28)

### 🚀 Features

- **auth:** store PKCE verifiers in per-flow slots to survive
overlapping flows
([#2569](https://github.com/supabase/supabase-js/pull/2569))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-08-11 11:32:52 +03:00
Ivan Vasilov 6b14df7724 chore: Bump vulnerable deps (#48387)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated Next.js, PostCSS, and tar package versions.
  * Added the required TypeScript native tooling where needed.
* Refined package configuration and dependency ordering across the
project.
  * Removed an unused empty dependency configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-30 14:23:43 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] b77f4f678c feat: update @supabase/*-js libraries to v2.110.9 (#48363)
This PR updates @supabase/*-js libraries to version 2.110.9.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.110.9
- Updated @supabase/auth-js to 2.110.9
- Updated @supabase/realtime-js to 2.110.9
- Updated @supabase/postgest-js to 2.110.9
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.110.9

## 2.110.9 (2026-07-27)

### 🩹 Fixes

- **auth:** downgrade stale refresh token console noise
([#2559](https://github.com/supabase/supabase-js/pull/2559))
- **realtime:** preserve presence refs
([#2566](https://github.com/supabase/supabase-js/pull/2566))
- **repo:** override sharp to >=0.35.0 to clear libvips advisory
([#2548](https://github.com/supabase/supabase-js/pull/2548))
- **repo:** populate symbols in sdk-compliance so capabilities are
verifiable ([#2547](https://github.com/supabase/supabase-js/pull/2547))
- **repo:** bump postcss, babel, next to clear audit advisories
([#2561](https://github.com/supabase/supabase-js/pull/2561))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vaibhav @7ttp

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-07-27 18:41:03 +03:00
Alaister YoungandAlaister Young 8d4d3b57e0 feat(studio): add tanstack variant to the studio docker image (#48091)
Makes the self-hosted Docker image buildable with the TanStack/Vite
build alongside the existing Next one. The Dockerfile's new
`STUDIO_FRAMEWORK` build arg (default: `next`) selects which framework
lands in the image — the same variable `scripts/dispatch.js` keys on
everywhere else, so `--build-arg STUDIO_FRAMEWORK=tanstack` is the
docker spelling of the existing switch. Both flavors assemble a
normalized `/srv` tree, so a single production stage serves either with
the same CMD (`node apps/studio/server.js`), port 3000, and healthcheck.

Unlike Next's self-contained standalone output, the Vite SSR bundle
externalizes studio's dependencies and resolves them from `node_modules`
at request time, so the tanstack runtime tree is a prod-only `pnpm
deploy` plus the built `dist/`. The boot smoke test runs a second time
against that pruned tree, so a runtime import that's missing from
`dependencies` fails the image build instead of 500ing the deployed
container — which is exactly how this PR caught four packages
misclassified as devDependencies (`braintrust` +
`@smithy/property-provider` via the AI routes, `libpg-query` via the
parse-query API route, `@radix-ui/react-use-escape-keydown` via the
Queues panel; split into its own commit).

**Changed:**
- `apps/studio/Dockerfile`: `ARG STUDIO_FRAMEWORK` selects `build-next`
/ `build-tanstack` stages via `FROM build-${STUDIO_FRAMEWORK}`; both
normalize into one production layout
- `apps/studio/package.json`: moved the four runtime-imported packages
from devDependencies to dependencies (versions unchanged)
- `apps/studio/vite.config.ts`: pinned `preview.host` to `127.0.0.1` —
the prerender step boots `vite preview` and crawls its resolved URL, and
the default `localhost` host lets the server bind the IPv6 loopback
while the crawler fetches `127.0.0.1`, which ECONNREFUSEDs the whole
build inside BuildKit containers
- `.github/workflows/studio-docker-build.yml`: builds the tanstack image
as a second step (reuses the first build's layer cache; job name
unchanged)

**Added:**
- `build:studio:docker:tanstack` root script

Note: the tanstack image is ~2.0GB vs ~1.2GB for Next (externalized
`node_modules`); shrinking it via file tracing is a follow-up. Nothing
self-hosters pull changes until a tanstack-built image is published —
this makes it buildable and CI-checked.

## To test

- `pnpm build:studio:docker` then run the image against a stack —
behavior unchanged (healthcheck `/api/platform/profile` 200, `/` 307s to
`/project/default`)
- `pnpm build:studio:docker:tanstack` then run that image with the same
env — same healthcheck, redirect, and data endpoints (projects, pg-meta)
respond 200; browser loads Project Overview / Table Editor with no
requests leaving the container
- Both verified locally against the CLI stack (`host.docker.internal`
env, container reports `healthy`)
- Vercel + e2e checks on this PR exercise the `preview.host` change on
their runners

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added TanStack-based Studio build support with a framework-selectable
Docker image.
  - Added a local build command for the TanStack Studio Docker image.
- **Build & Deployment**
- Updated the Studio Docker build workflow to also publish a
TanStack-tagged Studio image when relevant.
- **Bug Fixes**
- Improved `vite preview` behavior in containers by binding to IPv4
loopback.
  - Standardized the Studio container runtime port to `3000`.
- **Chores**
  - Updated Studio runtime packages to support the TanStack build.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-07-24 15:32:05 +00:00
Ivan Vasilov 2428bddcb5 chore: Bump vulnerable deps (#48178)
Fixes the following vulnerabilities:
- https://github.com/supabase/supabase/security/dependabot/3963
- https://github.com/supabase/supabase/security/dependabot/3963
- https://github.com/supabase/supabase/security/dependabot/3964
- https://github.com/supabase/supabase/security/dependabot/3965
- https://github.com/supabase/supabase/security/dependabot/3966
- https://github.com/supabase/supabase/security/dependabot/3927
- https://github.com/supabase/supabase/security/dependabot/3955
- https://github.com/supabase/supabase/security/dependabot/3913
- https://github.com/supabase/supabase/security/dependabot/3972
- https://github.com/supabase/supabase/security/dependabot/3959
- https://github.com/supabase/supabase/security/dependabot/3960
- https://github.com/supabase/supabase/security/dependabot/3916
- https://github.com/supabase/supabase/security/dependabot/3918
- https://github.com/supabase/supabase/security/dependabot/3947
- https://github.com/supabase/supabase/security/dependabot/3948
- https://github.com/supabase/supabase/security/dependabot/3956
- https://github.com/supabase/supabase/security/dependabot/3957
- https://github.com/supabase/supabase/security/dependabot/3958
- https://github.com/supabase/supabase/security/dependabot/3917
- https://github.com/supabase/supabase/security/dependabot/3919
- https://github.com/supabase/supabase/security/dependabot/3970
- https://github.com/supabase/supabase/security/dependabot/3928
- https://github.com/supabase/supabase/security/dependabot/3949
- https://github.com/supabase/supabase/security/dependabot/3950
- https://github.com/supabase/supabase/security/dependabot/3973
- https://github.com/supabase/supabase/security/dependabot/3920
- https://github.com/supabase/supabase/security/dependabot/3951

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated the bundled `tar` dependency to a newer patch version for
consistency and security across the workspace.
* Added/adjusted overrides to pin a few transitive dependencies to
specific versions.
* Normalized workspace configuration formatting and made minor
development configuration cleanup (no functional change).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-22 14:45:45 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] d847c48464 feat: update @supabase/*-js libraries to v2.110.8 (#48156)
This PR updates @supabase/*-js libraries to version 2.110.8.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.110.8
- Updated @supabase/auth-js to 2.110.8
- Updated @supabase/realtime-js to 2.110.8
- Updated @supabase/postgest-js to 2.110.8
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.110.8

## 2.110.8 (2026-07-21)

### 🩹 Fixes

- **auth:** downgrade aborted/transient fetch failures from
console.error to warn
([#2544](https://github.com/supabase/supabase-js/pull/2544))
- **functions:** clean up cross-signal abort listener on invoke() return
([#2487](https://github.com/supabase/supabase-js/pull/2487))
- **functions:** match response Content-Type case-insensitively
([#2515](https://github.com/supabase/supabase-js/pull/2515))
- **storage:** url-encode object key in CDN purge methods
([#2545](https://github.com/supabase/supabase-js/pull/2545))
- **supabase:** skip Node warning in Deno
([#2541](https://github.com/supabase/supabase-js/pull/2541))

### ❤️ Thank You

- Franco Kaddour @FrancoKaddour
- Katerina Skroumpelou @mandarini
- Pedro Henrique
- Vaibhav @7ttp
## v2.110.7

## 2.110.7 (2026-07-16)

### 🩹 Fixes

- **postgrest:** correct self-reference inference
([#2525](https://github.com/supabase/supabase-js/pull/2525))
- **realtime:** trigger set auth on INITIAL_SESSION event
([#2531](https://github.com/supabase/supabase-js/pull/2531))
- **realtime:** update phoenix to fix presence issue
([#2532](https://github.com/supabase/supabase-js/pull/2532))

### ❤️ Thank You

- Eduardo Gurgel
- Filipe Cabaço @filipecabaco
- Vaibhav @7ttp

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-07-22 14:30:30 +03:00
Ivan Vasilov 24ce0ba5f8 chore: migrate repo to pnpm v11 (#48033)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / dependency tooling update.

## What is the current behavior?

The repo is pinned to pnpm 10.24.0. Closes
https://linear.app/supabase/issue/FE-3673/migrate-the-repo-to-use-pnpm-v11.

## What is the new behavior?

The repo is pinned to pnpm 11.13.1, pnpm v11 workspace settings are
migrated to `allowBuilds`, and the Studio Dockerfile installs pnpm
11.13.1.

## Additional context

Validated with `CI=true mise exec node@22 -- pnpm install
--frozen-lockfile`, `mise exec node@22 -- pnpm run typecheck`, and `mise
exec node@22 -- pnpm run lint`; full Prettier check still fails on
existing generated docs/router files outside this migration.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated tooling requirements (pnpm **11.13.1**, Node **>=22.13**) and
aligned container build tooling accordingly.
* Adjusted package manager behavior (scoped registry override, update
notifications disabled) and workspace build/engine validation settings.

* **Maintenance**
* Updated `clean` scripts across apps/packages to remove only
build/cache artifacts (no longer delete installed dependencies).
* Reduced Turbo `clean` task output to **errors-only** for cleaner logs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-20 12:57:42 +02:00
Ivan Vasilov dc3c8684cc chore(deps): upgrade valtio to v2 (#48031)
Audited all proxy()/useSnapshot() usage against the v1→v2 migration
guide; no breaking changes apply (no reused proxy() inputs, no
promise-valued state, all consumers already client components).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated the Valtio dependency to a newer version for improved
compatibility.

* **Bug Fixes**
* Improved AI assistant persistence in IndexedDB so chat sessions
reliably save (while keeping only the most recent 20 messages per chat).
* Hardened tabs restoration from storage to fall back to fresh defaults
when data is missing, invalid, or fails validation.

* **Refactor**
* Switched multiple studio panels to use fresh initial-state factories
for initialization and reset reliability.
* Updated advisor state so the derived notification filter count is no
longer exposed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-17 15:51:54 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 360bae3871 feat: update @supabase/*-js libraries to v2.110.6 (#47968)
This PR updates @supabase/*-js libraries to version 2.110.6.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.110.6
- Updated @supabase/auth-js to 2.110.6
- Updated @supabase/realtime-js to 2.110.6
- Updated @supabase/postgest-js to 2.110.6
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.110.6

## 2.110.6 (2026-07-15)

### 🩹 Fixes

- **postgrest:** type hinted self-referencing embeds as arrays
([#2520](https://github.com/supabase/supabase-js/pull/2520))
- **realtime:** forward opts to send() in track()
([#2490](https://github.com/supabase/supabase-js/pull/2490))
- **supabase:** warn instead of throw for unrecognized sb_ API key
subtypes ([#2526](https://github.com/supabase/supabase-js/pull/2526))

### ❤️ Thank You

- Franco Kaddour @FrancoKaddour
- Katerina Skroumpelou @mandarini
## v2.110.5

## 2.110.5 (2026-07-14)

### 🩹 Fixes

- **supabase:** avoid edge runtime warning
([#2522](https://github.com/supabase/supabase-js/pull/2522))

### ❤️ Thank You

- Vaibhav @7ttp
## v2.110.4

## 2.110.4 (2026-07-14)

### 🩹 Fixes

- **functions:** stop sending API key in Authorization header for
function calls
([#2511](https://github.com/supabase/supabase-js/pull/2511))
- **realtime:** encode broadcast header fields as UTF-8
([#2516](https://github.com/supabase/supabase-js/pull/2516))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Pedro Henrique
## v2.110.3

## 2.110.3 (2026-07-13)

### 🩹 Fixes

- **auth:** preserve pkce verifier
([#2513](https://github.com/supabase/supabase-js/pull/2513))
- **postgrest:** pin tstyche target off floating latest
([#2509](https://github.com/supabase/supabase-js/pull/2509))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vaibhav @7ttp
## v2.110.2

## 2.110.2 (2026-07-09)

### 🩹 Fixes

- **auth:** clear local session on signout failures
([#2504](https://github.com/supabase/supabase-js/pull/2504))

### ❤️ Thank You

- Luc Peng

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-07-15 19:25:03 +03:00
Guilherme Souza fd5ec9fade Revert "feat: update @supabase/*-js libraries to v2.110.5" (#47918) (#47945)
Reverts #47918.

## Summary
- Reverts `@supabase/auth-js`, `@supabase/postgrest-js`,
`@supabase/realtime-js`, `@supabase/supabase-js` from 2.110.5 back to
2.110.1 in `pnpm-workspace.yaml` and `pnpm-lock.yaml`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated Supabase package versions to improve compatibility and
consistency across the project.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-14 20:21:19 -04:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 3ed7c8f522 feat: update @supabase/*-js libraries to v2.110.5 (#47918)
This PR updates @supabase/*-js libraries to version 2.110.5.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.110.5
- Updated @supabase/auth-js to 2.110.5
- Updated @supabase/realtime-js to 2.110.5
- Updated @supabase/postgest-js to 2.110.5
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.110.5

## 2.110.5 (2026-07-14)

### 🩹 Fixes

- **supabase:** avoid edge runtime warning
([#2522](https://github.com/supabase/supabase-js/pull/2522))

### ❤️ Thank You

- Vaibhav @7ttp
## v2.110.4

## 2.110.4 (2026-07-14)

### 🩹 Fixes

- **functions:** stop sending API key in Authorization header for
function calls
([#2511](https://github.com/supabase/supabase-js/pull/2511))
- **realtime:** encode broadcast header fields as UTF-8
([#2516](https://github.com/supabase/supabase-js/pull/2516))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Pedro Henrique
## v2.110.3

## 2.110.3 (2026-07-13)

### 🩹 Fixes

- **auth:** preserve pkce verifier
([#2513](https://github.com/supabase/supabase-js/pull/2513))
- **postgrest:** pin tstyche target off floating latest
([#2509](https://github.com/supabase/supabase-js/pull/2509))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vaibhav @7ttp
## v2.110.2

## 2.110.2 (2026-07-09)

### 🩹 Fixes

- **auth:** clear local session on signout failures
([#2504](https://github.com/supabase/supabase-js/pull/2504))

### ❤️ Thank You

- Luc Peng

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-07-14 18:22:18 +03:00
ad181489b1 feat(studio): adopt @sentry/tanstackstart-react server instrumentation on the TanStack build (#47724)
Stacked on #47666 (base `alaister/tanstack-sentry-init`; retarget to
`master` when that merges). **Supersedes #47721** (the manual
`@sentry/node` wrapper). Client stays on #47666's `@sentry/react` setup.

Adopts the official `@sentry/tanstackstart-react` SDK **on the server
only**, after a spike (#47723) evaluating the full unified client+server
SDK. The spike found the SDK's **browser**
`tanstackRouterBrowserTracingIntegration` is a broken no-op stub at
10.59.0/10.64.0 — so the client stays on `@sentry/react` (whose
equivalent integration is a real, working implementation, already
shipped in #47666). The **server** exports, however, are a clear upgrade
and slot in cleanly.

### What this adds (server-side, TanStack build only)
- **`instrument.server.mjs`** — `Sentry.init` from
`@sentry/tanstackstart-react`, mirroring `sentry.server.config.ts` +
`release: VERCEL_GIT_COMMIT_SHA`.
- **`start.ts`** — `sentryGlobalRequestMiddleware` +
`sentryGlobalFunctionMiddleware` at the front of the existing
`createStart(...)` middleware. **This is the win**: it captures request-
and server-function errors *including the ones swallowed into 500s* —
the exact class the manual wrapper (and the Next server SDK) miss.
- **`api/server.js` / `scripts/serve.js`** — gated
(`STUDIO_FRAMEWORK==='tanstack'`) instrument init +
`wrapFetchWithSentry` on the handler.
- **`vite.config.ts`** — `sentryTanstackStart({ …,
autoInstrumentMiddleware: false })` as the last plugin: source-map
upload + release injection (skips gracefully without an auth token).
Middleware is wired explicitly rather than via the plugin's
string-rewrite.

### Guarantees
- **Client untouched** — the `@sentry/nextjs`→`@sentry/react` alias and
#47666's client init are unchanged.
- **Next untouched** — `instrumentation.ts` / `sentry.server.config.ts`
etc. stay as-is; all new code is TanStack-gated.
- **No server SDK in the client bundle** — verified after build: no
`@sentry/node` / server middleware / `wrapFetchWithSentry` in
`dist/client/assets` (`start.ts`'s server import is tree-shaken out).

### Verified
TanStack build exit 0 (past `assertNoChunkCycles`), post-build server
boot served `/api/get-utc-time → 200`, `tsc --noEmit` clean,
prettier/eslint clean. Node smoke: no-DSN init is a clean no-op; wrapped
handler returns 200.

### To test (deploy with a server DSN)
Throw a server error from an `/api/*` route (or a `/_serverFn/*`) —
including one that gets turned into a 500 without rethrowing — and
confirm a server event in Sentry with `release` = the deploy SHA.
Compared to #47721, the swallowed-500 case should now be captured via
the middleware.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Sentry integration for the Studio app’s TanStack Start runtime,
including request and server-function instrumentation.
* Wrapped server request handling to capture errors reliably, with
tracing enabled.
* Updated build tooling to conditionally upload source maps when
credentials are present.

* **Bug Fixes**
* Improved resilience by safely falling back to a no-op Sentry setup if
instrumentation cannot be loaded.
* Ensured existing request protection remains enabled while adding
observability middleware.

* **Chores / Config**
* Added `SKIP_ASSET_UPLOAD` to the build environment list to control
cache/build behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-07-10 16:52:07 +08:00
a3f2c4ffc1 chore(deps): upgrade to TypeScript 7 (native compiler) (#47757)
Upgrades the monorepo to TypeScript 7.0.2, released 2026-07-08. `tsc` is
now the native Go compiler
([announcement](https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/))
— full turbo typecheck drops from ~56s to ~19s locally.

TS 7.0 ships **without a programmatic API** (it lands in 7.1), so this
uses Microsoft's recommended side-by-side setup: the `typescript` name
resolves to `@typescript/typescript6` (the 6.0 API republished) for API
consumers — typescript-eslint and Next.js build typechecking — while
`@typescript/native` (the real `typescript@7.0.2`) owns the `tsc` bin
that typecheck scripts run. Exactly one version of each is in the
lockfile; nothing imports the native package as a library. When 7.1 +
tool support lands we can collapse back to a single `typescript` dep in
the catalog.

**Changed:**
- `pnpm-workspace.yaml`: catalog aliases for `typescript` /
`@typescript/native`
- 17 package.json files: `@typescript/native` added beside each
`typescript` dep so every package's `tsc` is the native binary
- `apps/studio/tsconfig.json`: exclude `dist/` (gitignored build output)
from typechecking

**Fixed** (real type errors TS 6 under-reported):
- `packages/ui-patterns` CodeBlock: `borderLeft: null` → `undefined`
(`CSSProperties` doesn't accept null)
- `apps/www` CodeBlock: removed a JSX `@ts-ignore` comment that tsgo
doesn't honor and fixed what it masked (untyped `.js` theme objects,
possibly-undefined highlighter children)

⚠️ **Merge timing:** the new packages are inside pnpm's 3-day
`minimumReleaseAge` window until ~July 11. Installs from the committed
lockfile are unaffected (resolution is skipped), but anything that
forces a re-resolution before then will fail — hold off merging until
the window passes.

Note for editors: the compat package has no `lib/tsserver.js`, so VS
Code's "Use Workspace Version" won't work — use the bundled TS or the
TypeScript Native Preview extension.

## To test

- `pnpm install && pnpm typecheck` — all 15 tasks green, and
`./node_modules/.bin/tsc --version` prints 7.0.2
- `pnpm lint --filter=studio` — typescript-eslint still parses (resolves
the 6.0 API)
- `pnpm build --filter=design-system` (or any Next app) — Next's
tsconfig validation and build typecheck still work
- CodeBlock rendering on www (syntax highlighting, line highlights
with/without border) — the two fixes are behavior-neutral but worth an
eyeball

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements / New Features**
* Enhanced TypeScript tooling support across the workspace for smoother
development builds and checks.

* **Bug Fixes**
  * Code blocks render more reliably when content is empty or missing.
  * Highlighted code line styling applies more consistently.

* **Maintenance**
* Studio TypeScript builds now avoid including generated output (such as
`dist`) during compilation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-07-09 14:07:17 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 69121ed8e6 feat: update @supabase/*-js libraries to v2.110.1 (#47687)
This PR updates @supabase/*-js libraries to version 2.110.1.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.110.1
- Updated @supabase/auth-js to 2.110.1
- Updated @supabase/realtime-js to 2.110.1
- Updated @supabase/postgest-js to 2.110.1
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.110.1

## 2.110.1 (2026-07-07)

### 🩹 Fixes

- **auth:** defer init-time notifications until initializePromise
resolves ([#2498](https://github.com/supabase/supabase-js/pull/2498))
- **realtime:** suppress disconnected status from onHeartbeat consumers
([#2496](https://github.com/supabase/supabase-js/pull/2496))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.110.0

## 2.110.0 (2026-06-30)

### 🚀 Features

- **repo:** drop Node.js 20 support
([#2482](https://github.com/supabase/supabase-js/pull/2482))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.109.0

## 2.109.0 (2026-06-30)

### 🚀 Features

- **auth:** add custom_claims_allowlist to custom providers admin API
([#2473](https://github.com/supabase/supabase-js/pull/2473))
- **realtime:** add postgres_changes filter builder, new operators and
select ([#2463](https://github.com/supabase/supabase-js/pull/2463))
- **storage:** expose purgeCache for buckets and single objects
([#2429](https://github.com/supabase/supabase-js/pull/2429))

### 🩹 Fixes

- **functions:** honor a caller's Content-Type override regardless of
casing ([#2455](https://github.com/supabase/supabase-js/pull/2455))
- **realtime:** pin @supabase/phoenix and browser test CDN deps
([#2457](https://github.com/supabase/supabase-js/pull/2457))
- **realtime:** add replication connection system message option
([#2470](https://github.com/supabase/supabase-js/pull/2470))
- **storage:** keep sortBy defaults when list() is given a partial
sortBy ([#2454](https://github.com/supabase/supabase-js/pull/2454))

### ❤️ Thank You

- Anubhav Anand @i-anubhav-anand
- Cemal Kılıç @cemalkilic
- Claude Opus 4.8 (1M context)
- Filipe Cabaço @filipecabaco
- Katerina Skroumpelou @mandarini
- Lenny
- Rodrigo Mansueli @mansueli

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-07-07 17:26:15 +03:00
74881cbb73 feat: render the mcp config component as markdown (#47292)
Renders the MCP config component as markdown for static markdown builds.
Currently we have no special case for `<McpConfigPanel />`, so it gets
stripped out during markdown rendering. This adds a static markdown
version of this component that renders all agents/tools consecutively.

Adds a new `McpConfigPanel.md.tsx` component that reuses data structures
used by `McpConfigPanel.tsx` but renders as markdown instead of React.
Instead of building the markdown via string concatenation, we use
[supabase-community/mdast-jsx](https://github.com/supabase-community/mdast-jsx)
which allows you to author markdown using JSX (providing type safety,
better DX, maintainability). E.g.

```jsx
<code lang="json" value='{ "key": "value" }' />
```
produces:
````md
```json
{ "key": "value" }
```
````

## Preview

https://docs-git-feat-mcp-config-markdown-supabase.vercel.app/docs/guides/ai-tools/mcp.md

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

- **New Features**
- Added a docs-only MCP configuration panel with client-specific setup
steps, deep links, and generated configuration snippets.
- Enhanced guide generation to render richer, component-produced
markdown content.

- **Bug Fixes**
- Improved MCP config serialization and display for consistent
JSON/YAML/TOML output.

- **Refactor**
- Centralized MCP client metadata, instruction content, and config
build/serialization logic for reuse.

- **Chores**
- Expanded package exports for MCP URL builder assets and utilities;
improved runtime code-block language validation and updated PNG asset
typing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-07-02 14:00:33 +02:00
Ivan Vasilov 0361d1b727 chore: Remove CDN loading for the Monaco editor in all environments (#47182)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Standardized Monaco Editor package versions across the workspace using
the shared dependency catalog.
* **Bug Fixes**
* Improved Monaco initialization by configuring asset loading only on
the client and serving Monaco assets from a single base-path URL
(removing platform-specific switching).
* Streamlined Monaco stylesheet injection in Studio’s document
rendering.
* **New Features**
* Added/updated Monaco language support in Studio, including GraphQL,
SQL, and PostgreSQL, with refreshed HTML, JSON, and CSS editor modes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-30 13:57:31 +02:00
Ivan Vasilov 631209f7ce chore: Bump vulnerable dependencies (#47269)
Bump several packages:
- Bump all instances of dompurify (patch version bump)
- Bump `posthog-js` to get a newer version of `@opentelemetry/core`
- Bump `@sentry/nextjs` to get a newer version of `@opentelemetry/core`
- Bump `redocly-cli` to get a newer version of `@opentelemetry/core`
- Bump `undici`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated several project dependencies to newer versions, including
documentation tooling, analytics, and error-tracking packages.
* These updates may improve stability, compatibility, and access to the
latest fixes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-25 08:50:27 +02:00
9eab4f8fbf build(studio): Vite/TanStack-Start build pipeline behind flag (stack 1/6, from #46424) (#47107)
**Stack 1/6** of the TanStack Start migration (#46424), split into
reviewable, independently-mergeable PRs.

> [!IMPORTANT]
> **Next stays the default and only active framework after this PR.**
This wires up the Vite/TanStack-Start build pipeline behind the
`STUDIO_FRAMEWORK` flag, but there are no TanStack routes yet — so the
TanStack build isn't functional or tested until later PRs in the stack.
Nothing about the Next build, dev, or deploy changes behaviourally here.

## What's in this PR
- **Dispatch:** `dev`/`build`/`start` now go through
`scripts/dispatch.js`, which runs the Next variant unless
`STUDIO_FRAMEWORK=tanstack`. The original commands are preserved as
`dev:next`/`build:next`/`start:next`.
- **Build pipeline:** `vite.config.ts`, `serve.js`, `smoke-server.mjs`,
vite/tanstack deps, `turbo.jsonc`.
- **`tsconfig.json`:** `jsx: react-jsx`, `moduleResolution: Bundler`,
`target: ES2022`. Because `include` is `**/*.ts(x)`, this re-typechecks
the whole app, so the companion adaptations below land with it.
- **Shared adaptations (companions to the tsconfig change):**
`BufferSource` casts, `packages/ui` unused-`React` import removals, etc.
- **Routing/middleware plumbing:** `next.config.ts` +
`redirects.shared.ts` (redirect rules now shared with `vercel.ts`),
`proxy.ts`/`start.ts` middleware + `hosted-api-allowlist.ts`.

## Verification
Run locally off `master`: frozen install ✓, `studio` typecheck ✓, **Next
build ✓** (compiles + generates all routes), lint ratchet ✓ ("some rules
improved"), prettier ✓.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a hosted API endpoint allowlist to return 404 for non-supported
`/api/*` routes.
* Introduced a TanStack route-migration checklist and expanded TanStack
Start routing support.
* **Improvements**
* Enhanced deployment refresh/detection by tightening cookie handling
for “latest deployment” updates.
* Centralized redirect/maintenance-mode rules for consistent platform vs
self-hosted behavior.
* Improved production serving with a dedicated static + proxy server and
a post-build smoke test.
* **Dependencies**
* Updated TanStack-related packages and React Table/query tooling
versions.
* **Documentation / Chores**
* Updated formatting and tooling config; added shared build environment
parsing utilities.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-06-24 17:55:22 +08:00
Ivan Vasilov 8d46dafc0a chore: Bump vulnerable dependencies (#47029)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Chores**
* Updated shared development dependencies including build tools and code
transformation utilities to latest compatible versions for improved
performance and stability across the workspace.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-17 14:18:53 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] f761c66a9f feat: update @supabase/*-js libraries to v2.108.2 (#46927)
This PR updates @supabase/*-js libraries to version 2.108.2.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.108.2
- Updated @supabase/auth-js to 2.108.2
- Updated @supabase/realtime-js to 2.108.2
- Updated @supabase/postgest-js to 2.108.2
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.108.2

## 2.108.2 (2026-06-15)

### 🩹 Fixes

- **auth:** preserve valid session on refresh failure and cooldown
repeat failures
([#2436](https://github.com/supabase/supabase-js/pull/2436))
- **realtime:** clarify httpSend() 404 error and server migration note
([#2444](https://github.com/supabase/supabase-js/pull/2444))
- **release:** pin Deno and bound JSR publish to survive stranded-task
hangs ([#2439](https://github.com/supabase/supabase-js/pull/2439))
- **release:** restore JSR publish flags and enable for beta
([#2440](https://github.com/supabase/supabase-js/pull/2440))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.108.1

## 2.108.1 (2026-06-09)

### 🩹 Fixes

- **ci:** forward DOGFOOD_APP_CLIENT_ID to dogfood workflow
([#2434](https://github.com/supabase/supabase-js/pull/2434))
- **postgrest:** then typing
([#2349](https://github.com/supabase/supabase-js/pull/2349))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vaibhav @7ttp

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-06-16 10:19:28 +03:00
Ivan Vasilov 4cdbe67980 chore: Bump vulnerable dependencies (#46840)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated React Router packages to v7.17.0 for improved routing
stability.
* Adjusted workspace dependency governance and overrides for more
consistent installs.
  * Removed an obsolete PostCSS re-export.

* **New Features**
* Integrated Tailwind into the build pipeline to enable utility-first
styling.

* **Style**
* Added global base styles to standardize border color across UI
elements.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 10:12:06 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 10d0b63950 feat: update @supabase/*-js libraries to v2.108.0 (#46740)
This PR updates @supabase/*-js libraries to version 2.108.0.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.108.0
- Updated @supabase/auth-js to 2.108.0
- Updated @supabase/realtime-js to 2.108.0
- Updated @supabase/postgest-js to 2.108.0
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.108.0

## 2.108.0 (2026-06-08)

### 🚀 Features

- **auth:** auth.resend() consistent confirmation flow
([#2144](https://github.com/supabase/supabase-js/pull/2144))

### 🩹 Fixes

- **auth:** do not console.error AuthApiError already returned through
contract ([#2428](https://github.com/supabase/supabase-js/pull/2428))
- **postgrest:** pass request headers as plain object for
RN/custom-fetch compatibility
([#2414](https://github.com/supabase/supabase-js/pull/2414))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Lawrence Li @weilirs
- MaitreyeeDeshmukh

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-06-08 16:22:02 +03:00
Ivan Vasilov 1673012bc7 chore: Bump vulnerable dependencies (#46624)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated build tools and development dependencies across the project
  * Upgraded Vue framework and related tooling to latest versions
  * Updated TanStack React Start dependency
* Refined dependency resolution settings to improve build stability and
performance

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-04 12:07:23 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 4c474068be feat: update @supabase/*-js libraries to v2.107.0 (#46586)
This PR updates @supabase/*-js libraries to version 2.107.0.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.107.0
- Updated @supabase/auth-js to 2.107.0
- Updated @supabase/realtime-js to 2.107.0
- Updated @supabase/postgest-js to 2.107.0
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.107.0

## 2.107.0 (2026-06-02)

### 🚀 Features

- **auth:** remove navigator.locks-based mutex; introduce commit guard +
dispose() ([#2392](https://github.com/supabase/supabase-js/pull/2392))
- **realtime:** allow httpSend to send binary payload
([#2400](https://github.com/supabase/supabase-js/pull/2400))
- **supabase:** update X-Client-Info to structured metadata format
([#2359](https://github.com/supabase/supabase-js/pull/2359))

### 🩹 Fixes

- **auth:** return AuthInvalidJwtError from getClaims for expired JWT
([#2395](https://github.com/supabase/supabase-js/pull/2395))
- **auth:** recognize ?error= redirects in implicit grant gate
([#2407](https://github.com/supabase/supabase-js/pull/2407))
- **auth): revert fix(auth:** encode client-id in oauth requests
([#2383](https://github.com/supabase/supabase-js/pull/2383),
[#2417](https://github.com/supabase/supabase-js/pull/2417))
- **postgrest:** return a structured error for non-JSON body on
successful responses
([#2398](https://github.com/supabase/supabase-js/pull/2398))
- **release:** pin workspace:* sibling deps before JSR publish
([#2418](https://github.com/supabase/supabase-js/pull/2418))
- **release:** publish gotrue-js legacy mirror via pnpm
([#2419](https://github.com/supabase/supabase-js/pull/2419))

### ❤️ Thank You

- Claude Opus 4.7 (1M context)
- Claude Sonnet 4.6
- Eduardo Gurgel
- Guilherme Souza
- Katerina Skroumpelou @mandarini
- Omar Al Matar @Bewinxed
- youcef zr @youcefzemmar
- youcefzemmar

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-06-02 17:56:13 +03:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 91c928e345 feat: update @supabase/*-js libraries to v2.106.2 (#46324)
This PR updates @supabase/*-js libraries to version 2.106.2.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.106.2
- Updated @supabase/auth-js to 2.106.2
- Updated @supabase/realtime-js to 2.106.2
- Updated @supabase/postgest-js to 2.106.2
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.106.2

## 2.106.2 (2026-05-25)

### 🩹 Fixes

- **auth:** restore signup user response
([#2391](https://github.com/supabase/supabase-js/pull/2391))
- **misc:** add react-native export condition for Hermes-safe resolution
([#2393](https://github.com/supabase/supabase-js/pull/2393))

### ❤️ Thank You

- Myroslav Hryhschenko @BLOCKMATERIAL
- Vaibhav @7ttp
## v2.106.1

## 2.106.1 (2026-05-20)

### 🩹 Fixes

- **auth:** encode client-id in oauth requests
([#2383](https://github.com/supabase/supabase-js/pull/2383))
- **misc:** hide dynamic import from hermesc
([#2381](https://github.com/supabase/supabase-js/pull/2381))

### ❤️ Thank You

- Etienne Stalmans @staaldraad
- Katerina Skroumpelou @mandarini

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-05-25 15:43:03 +03:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] ba34c1f6e9 feat: update @supabase/*-js libraries to v2.106.0 (#46068)
This PR updates @supabase/*-js libraries to version 2.106.0.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.106.0
- Updated @supabase/auth-js to 2.106.0
- Updated @supabase/realtime-js to 2.106.0
- Updated @supabase/postgest-js to 2.106.0
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.106.0

## 2.106.0 (2026-05-18)

### 🚀 Features

- **supabase:** W3C/OpenTelemetry trace context propagation
([#2163](https://github.com/supabase/supabase-js/pull/2163))

### 🩹 Fixes

- **auth:** return null user and session for email_change
single-confirmation verifyOtp
([#2378](https://github.com/supabase/supabase-js/pull/2378))
- **release:** mark @supabase/tracing private and snapshot it for JSR
([#2370](https://github.com/supabase/supabase-js/pull/2370))
- **storage:** make StreamDownloadBuilder implement Promise and memoize
executor ([#2367](https://github.com/supabase/supabase-js/pull/2367))

### ❤️ Thank You

- Claude Sonnet 4.5
- Guilherme Souza
- Katerina Skroumpelou @mandarini
- oniani1

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-05-19 16:27:42 +03:00
Gildas Garcia 86a3f8b03d chore: upgrade to react-19 (#45886)
- Most changes are related to either types or `useRef` usages (it now
requires an initial value).
- also updated `vaul` to its latest version and haven't noticed any
change ([design-system
demo](https://design-system-git-react-19-supabase.vercel.app/design-system/docs/components/drawer))

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Upgraded workspace to React 19.

* **Bug Fixes**
* Improved null-safety and ref handling across editors, UI components,
shortcuts, and markdown/image rendering to reduce runtime errors.
* Safer event/timeout/interval cleanup and more robust command/context
handling.

* **Chores**
  * Bumped vaul dependency versions.

* **Documentation**
* Type and TypeScript accuracy improvements for clearer developer
feedback.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45886)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-15 16:04:41 +02:00
Ivan Vasilov 380c917b94 chore: Bump vulnerable dependencies (#45876)
- Bump various vulnerable dependencies, `nitropack`, `mermaid`, `hono`,
`protobufjs`, `fast-xml-builder` and `fast-uri`.
- Add `babel/core` to `studio` to stabilize the dependency resolving for
`studio`.
- Also deduped `cheerio`, `c12`, `browserslist`, `unstorage` and
`@mdx-js/mdx` since they were present as multiple similar versions.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Added development dependency for the studio application build tooling
* Updated workspace configuration to refine dependency exclusion
settings

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45876)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-13 14:50:01 +02:00
Ivan Vasilov bdc8d07632 chore: Add blockExoticSubdeps to prevent GitHub URLs and tarballs (#45817)
This pull request introduces a configuration update to the
`pnpm-workspace.yaml` file. The most significant change is the addition
of the `blockExoticSubdeps: true` setting, which helps prevent the
installation of potentially problematic or non-standard subdependencies
across the workspace. There is also a minor adjustment in the
`overrides` section, but it does not result in any functional changes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Enhanced package dependency configuration to prevent exotic
subdependencies and improve installation reliability.
  * Reorganized dependency override specifications for consistency.

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45817)

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-12 09:41:21 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] e46ee776b4 feat: update @supabase/*-js libraries to v2.105.4 (#45717)
This PR updates @supabase/*-js libraries to version 2.105.4.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.105.4
- Updated @supabase/auth-js to 2.105.4
- Updated @supabase/realtime-js to 2.105.4
- Updated @supabase/postgest-js to 2.105.4
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.105.4

## 2.105.4 (2026-05-08)

### 🩹 Fixes

- **auth:** return null from getItemAsync on JSON parse failure
([#2336](https://github.com/supabase/supabase-js/pull/2336))
- **postgrest:** restore non-Error abort detection in fetch catch
([#2335](https://github.com/supabase/supabase-js/pull/2335))
- **realtime:** guard sessionStorage access in restricted-storage
browsers ([#2339](https://github.com/supabase/supabase-js/pull/2339))

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-05-08 18:02:58 +03:00
Charis cd3f1776c8 bump next patch version (#45699)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
  * Bumped Next.js versions used by docs and the workspace.
* Adjusted workspace dependency exclusion list to add Next-related
entries and remove a prior exclusion.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-07 18:44:15 -04:00
Ivan Vasilov b6a307f079 chore: Bump vulnerable dependencies (#45634)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated core SDK dependencies to latest compatible versions for
improved system stability and security.
* Enhanced workspace dependency configuration management by expanding
and reorganizing package constraints to optimize compatibility across
all modules and reduce potential build conflicts.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-06 14:02:01 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] cc59344000 feat: update @supabase/*-js libraries to v2.105.3 (#45541)
This PR updates @supabase/*-js libraries to version 2.105.3.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.105.3
- Updated @supabase/auth-js to 2.105.3
- Updated @supabase/realtime-js to 2.105.3
- Updated @supabase/postgest-js to 2.105.3
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.105.3

## 2.105.3 (2026-05-04)

### 🩹 Fixes

- **auth:** narrow OAuth/CustomProvider types to fix downstream consumer
typecheck ([#2326](https://github.com/supabase/supabase-js/pull/2326))
## v2.105.2

## 2.105.2 (2026-05-04)

### 🩹 Fixes

- **auth:** forward lockAcquireTimeout to SupabaseAuthClient
([#2309](https://github.com/supabase/supabase-js/pull/2309))
- **auth:** add toJSON to WebAuthnError for correct JSON serialization
([#2317](https://github.com/supabase/supabase-js/pull/2317))
- **misc:** widen enum-like unions with (string & {}) for forward compat
([#2303](https://github.com/supabase/supabase-js/pull/2303))
- **misc:** reduce any usage across packages
([#2314](https://github.com/supabase/supabase-js/pull/2314))
- **postgrest:** unify insert/upsert signatures
([#2315](https://github.com/supabase/supabase-js/pull/2315))

### ❤️ Thank You

- Muzzaiyyan Hussain @MuzzaiyyanHussain
## v2.105.1

## 2.105.1 (2026-04-28)

### 🩹 Fixes

- **postgrest:** query reassignment regression
([#2292](https://github.com/supabase/supabase-js/pull/2292))
- **realtime:** surface real Error on transport-level CHANNEL_ERROR
([#2299](https://github.com/supabase/supabase-js/pull/2299))

### ❤️ Thank You

- Vaibhav @7ttp
## v2.105.0

## 2.105.0 (2026-04-27)

### 🚀 Features

- **auth:** add passkey support with WebAuthn registration,
authentication, and management
([#2283](https://github.com/supabase/supabase-js/pull/2283))
- **realtime:** Realtime deferred disconnect
([#2282](https://github.com/supabase/supabase-js/pull/2282))

### 🩹 Fixes

- **postgrest:** narrow column types after not(column, is, null)
([#2264](https://github.com/supabase/supabase-js/pull/2264))
- **realtime:** annotate Timer/Vsn getters to avoid deep phoenix imports
([#2284](https://github.com/supabase/supabase-js/pull/2284))
- **storage:** apply metadata, headers, and cacheControl dedupe to
uploadToSignedUrl
([#2275](https://github.com/supabase/supabase-js/pull/2275))
- **storage:** forward duplex option for stream uploads via
uploadToSignedUrl
([#2289](https://github.com/supabase/supabase-js/pull/2289))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- oniani1

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-05-06 12:43:05 +03:00
Ivan Vasilov 97a8df0a23 feat: Handle the classic-dark theme in www and docs apps (#45214)
This PR fixes a bug where a user might choose `classic-dark` as a theme
in `studio` but then `docs` and `marketing` apps will look weird.

To test:
- Change the localStorage value of `theme` to `classic-dark`
- Open `www` and `docs` apps, they should look ok

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a new "classic-dark" theme option for enhanced visual
customization.

* **Improvements**
* Unified and simplified theme handling across apps for more consistent
behavior.
* Improved system-theme detection and smoother transitions when
switching themes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-05 16:18:46 +02:00
Ivan Vasilov 0dec08c96f chore: Bump vulnerable dependencies (#45513)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Upgraded the UUID library to a newer major version across apps and
removed a now-unneeded dev dependency.
  * Pinned PostCSS to a workspace-specific version to stabilize builds.
* **Refactor**
* Improved internal identifier generation for more consistent behavior
without changing outward functionality.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-04 13:41:08 +02:00
Ivan VasilovandJordi Enric 56de26fe22 chore: Migrate the monorepo to use Tailwind v4 (#45318)
This PR migrates the whole monorepo to use Tailwind v4:
- Removed `@tailwindcss/container-queries` plugin since it's included by
default in v4,
- Bump all instances of Tailwind to v4. Made minimal changes to the
shared config to remove non-supported features (`alpha` mentions),
- Migrate all apps to be compatible with v4 configs,
- Fix the `typography.css` import in 3 apps,
- Add missing rules which were included by default in v3,
- Run `pnpm dlx @tailwindcss/upgrade` on all apps, which renames a lot
of classes
- Rename all misnamed classes according to
https://tailwindcss.com/docs/upgrade-guide#renamed-utilities in all
apps.

---------

Co-authored-by: Jordi Enric <jordi.err@gmail.com>
2026-04-30 10:53:24 +00:00
Ivan Vasilov 308cd791a2 chore: Prep work for migrating to Tailwind v4 (#45285)
This PR preps the monorepo for a migration to Tailwind v4:
- Bump all Tailwind dependencies and libraries to the latest possible
version, while still compatible with Tailwind 3.
- Cleans up obsolete Tailwind 3 specific options and configs.
- Cleans up unused CSS files and fixes the CSS imports.
- Migrates all `important` uses in `@apply` lines to using the `!`
prefix.
- Move `typography.css` to the `config` package and import it from the
apps.
- Migrated all occurrences of `flex-grow`, `flex-shrink`,
`overflow-clip` and `overflow-ellipsis` since they're deprecated and
will be removed in Tailwind 4.
- Make the default theme object typesafe in the `ui` package.
- Migrate all `bg-opacity`, `border-opacity`, `ring-opacity` and
`divider-opacity` to the new format where they're declared as part of
the property color.
- Bump and unify all imports of `postcss` dependency.
2026-04-28 11:33:53 +02:00
Gildas GarciaandIvan Vasilov 7f4b02f2a7 chore: update radix (#45111)
## Problem

In order to update to react 19, we need to update several dependencies

## Solution

- migrate to the `radix` umbrella package to ease upgrade
- update some dependencies


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Consolidated Radix UI usage to a single unified package across apps
and packages, updated package manifests and workspace catalog entries.
No user-facing behavior, visuals, or public APIs changed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-04-27 11:03:28 +02:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] f9df7aa71a feat: update @supabase/*-js libraries to v2.104.1 (#45154)
This PR updates @supabase/*-js libraries to version 2.104.1.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.104.1
- Updated @supabase/auth-js to 2.104.1
- Updated @supabase/realtime-js to 2.104.1
- Updated @supabase/postgest-js to 2.104.1
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.104.1

## 2.104.1 (2026-04-23)

### 🩹 Fixes

- **auth:** emit PASSWORD_RECOVERY event for PKCE recovery flows
([#2272](https://github.com/supabase/supabase-js/pull/2272))
- **postgrest:** restore runtime test files to tstyche scope
([#2266](https://github.com/supabase/supabase-js/pull/2266))
- **supabase:** propagate custom fetch to realtime client
([#2267](https://github.com/supabase/supabase-js/pull/2267))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-04-24 09:08:01 +03:00
Matt Rossman c0c6f70f02 chore(studio): bump braintrust 3.4.0 → 3.9.0 (#44729)
Bumps braintrust from 3.4.0 to ~~3.7.1~~ 3.9.0

~~Notable fix: v3.7.0 preserves the returned promise in tracing channel
hooks, which should resolve incorrect duration reporting in the
dashboard (braintrustdata/braintrust-sdk-javascript#1617)~~

3.9.0 includes this fix for double counted durations
https://github.com/braintrustdata/braintrust-sdk-javascript/pull/1769

See eval results in comment below, this fixes the issue where LLM
Duration was clocking in larger than total Duration.

<img width="2384" height="1548" alt="CleanShot 2026-04-21 at 09 27
36@2x"
src="https://github.com/user-attachments/assets/7ad5a75c-e3c4-44e1-98d8-ad4849049f7a"
/>


Closes AI-578

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated Braintrust dependency to version 3.9.0

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 10:17:36 -04:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] 7236b699ad feat: update @supabase/*-js libraries to v2.104.0 (#45047)
This PR updates @supabase/*-js libraries to version 2.104.0.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.104.0
- Updated @supabase/auth-js to 2.104.0
- Updated @supabase/realtime-js to 2.104.0
- Updated @supabase/postgest-js to 2.104.0
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.104.0

## 2.104.0 (2026-04-20)

### 🚀 Features

- **storage:** extract shared header normalization utility
([#2251](https://github.com/supabase/supabase-js/pull/2251))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.103.3

## 2.103.3 (2026-04-16)

### 🩹 Fixes

- **realtime:** throw Error objects instead of bare strings
([#2256](https://github.com/supabase/supabase-js/pull/2256))
- **storage:** correct signedUrl type to allow null in createSignedUrls
([#2254](https://github.com/supabase/supabase-js/pull/2254))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- oniani1

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-04-20 14:45:45 +03:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] f575b39219 feat: update @supabase/*-js libraries to v2.103.2 (#44903)
This PR updates @supabase/*-js libraries to version 2.103.2.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.103.2
- Updated @supabase/auth-js to 2.103.2
- Updated @supabase/realtime-js to 2.103.2
- Updated @supabase/postgest-js to 2.103.2
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.103.2

## 2.103.2 (2026-04-15)

### 🩹 Fixes

- **auth:** include Cloudflare error codes in NETWORK_ERROR_CODES
([#2239](https://github.com/supabase/supabase-js/pull/2239))
- **auth:** remove Prettify wrapper from exported types for TypeDoc
expansion ([#2250](https://github.com/supabase/supabase-js/pull/2250))
- **misc:** add explicit return types to toJSON methods for JSR compat
([#2252](https://github.com/supabase/supabase-js/pull/2252))
- **storage:** remove client-side signed URL render endpoint
normalization
([#2249](https://github.com/supabase/supabase-js/pull/2249))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vansh Sharma @Vansh1811
## v2.103.1

## 2.103.1 (2026-04-15)

### 🩹 Fixes

- **auth:** add toJSON to AuthError for correct JSON serialization
([#2238](https://github.com/supabase/supabase-js/pull/2238))
- **postgrest:** handle bigint rpc
([#2245](https://github.com/supabase/supabase-js/pull/2245))
- **storage:** add toJSON to StorageError for correct JSON serialization
([#2246](https://github.com/supabase/supabase-js/pull/2246))
- **storage:** apply empty transform check to download and getPublicUrl
([#2219](https://github.com/supabase/supabase-js/pull/2219))

### ❤️ Thank You

- oniani1
- Vaibhav @7ttp

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-04-16 16:14:48 +03:00