mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
932b5dc3b85bda3cb83afa8a2da9fb423ce9727b
37397
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
932b5dc3b8 |
Remove skills page from ui library (#47947)
<img width="1033" height="861" alt="image" src="https://github.com/user-attachments/assets/54a104df-1db9-4b97-89db-6eec671b3af7" /> Removes the above AI Skills page from our ui library and instead redirects to the more up to date ai skills docs page. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a direct “Install Skills” link to the AI Skills documentation guide. * Added a permanent redirect from the legacy prompts URL to the new AI Skills guide. * **Documentation** * Updated the docs side navigation to list component pages under “Blocks”. * Removed the AI Skills page content and its navigation/search entries. * Removed the AI editor rules documentation/registry entries, so they no longer appear in the generated documentation set. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
069051b032 |
test(studio): cover Supabase API key formats in project client tests (#47960)
Adds a contract test that runs `createProjectSupabaseClient()` against the real `@supabase/supabase-js` for each Supabase API key format (temporary, publishable, secret, legacy JWT), asserting that client construction succeeds. Also replaces the placeholder key fixtures in the existing unit tests with realistically shaped ones. Previously the tests mocked the SDK entirely and used keys that don't resemble real formats, so an SDK version that rejects a valid key at construction (as `@supabase/supabase-js` 2.110.4 and 2.110.5 did, reverted in #47945 and fixed in supabase/supabase-js#2526) passed CI unnoticed; with this test, such a regression fails on the dependency bump PR itself. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added coverage confirming project clients work with temporary, publishable, secret, and legacy API key formats. * Updated test scenarios to use realistic temporary API key values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c1bd941598 |
docs: clarify edge function deployment size limits (5MB server-side vs 20MB local) (#47941)
<!-- ccr-slack-attribution --> _Requested by **Lakshan Perera** · [Slack thread](https://supabase.slack.com/archives/C023E4L60R3/p1784055775538959?thread_ts=1784055775.538959&cid=C023E4L60R3)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? Both the "Edge Function bundle size issues" troubleshooting page and the Edge Functions "Limits" page stated only a single **20 MB** limit. In practice, that 20 MB figure applies only to **local bundling** with the Supabase CLI. When a function is deployed via the **Management API or Dashboard**, bundling runs server-side and is capped at **5 MB** due to an infrastructure (Lambda) limit. Customers deploying that way were surprised to hit an error like `Function source code exceeds the maximum deployment size (5 MB). Reduce the size of your function and try again.` even though the docs implied 20 MB was available. ## What is the new behavior? Both pages now state the distinction explicitly: - **Local bundling (Supabase CLI):** up to **20 MB**. - **Server-side bundling (Management API or Dashboard):** up to **5 MB**. The troubleshooting page also adds a "Deploying larger functions" section pointing customers at the workaround: if a function is under 20 MB but over the 5 MB server-side limit, bundle it locally by running `supabase functions deploy` with the `--use-docker` flag to force local bundling and get the higher limit. ## Additional context **How / files changed:** - `apps/docs/content/troubleshooting/edge-function-bundle-size-issues.mdx` — rewrote the intro to describe both limits, added the "Deploying larger functions" workaround section, and fixed the frontmatter `keywords` (replaced `"10MB"` with `"5MB"` and `"20MB"`). - `apps/docs/content/guides/functions/limits.mdx` — updated the "Maximum Function Size" line to list both the 20 MB local and 5 MB server-side limits. Before, both pages said only 20 MB, so customers deploying via the API/Dashboard were surprised by a 5 MB error; after, both pages state the 5 MB server-side vs 20 MB local distinction and point to local bundling as the workaround. --- _Generated by [Claude Code](https://claude.ai/code/session_019bBXmQTRBWJbo3UTpfjPLU)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
13330e6328 |
fix(ui): expandable video preview image (#47964)
## What kind of change does this PR introduce? Restore preview image on ExpandableVideo trigger component. ## What is the current behavior? <img width="1441" height="698" alt="Screenshot 2026-07-15 at 14 08 58" src="https://github.com/user-attachments/assets/bdb1c4be-71a9-4601-b5c9-ab4fc97c48d1" /> <img width="1273" height="701" alt="Screenshot 2026-07-15 at 14 09 05" src="https://github.com/user-attachments/assets/b8026bcc-3d43-4faa-873b-1745b32c166c" /> ## What is the new behavior? <img width="1434" height="678" alt="Screenshot 2026-07-15 at 14 08 53" src="https://github.com/user-attachments/assets/8a3e64d1-5fe7-4ab9-a71b-3de5808d28b9" /> <img width="1160" height="672" alt="Screenshot 2026-07-15 at 14 08 48" src="https://github.com/user-attachments/assets/db598a47-ed8e-435b-b3ef-8ae9e76761a2" /> --- Also fixed a border-b issue on the PartnerCatalogDetail. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added thumbnail previews for partner catalog YouTube videos. - Improved video preview presentation with clearer overlays and stronger image blur. - **Bug Fixes** - Updated image loading support for YouTube thumbnail URLs. - Refined sticky tab header spacing and alignment while scrolling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
93e1631f19 |
fix: class name for text on infoicon (#47933)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Class name was bodged on `InfoIcon`. It was `text-background-surface-200`, think after recent update it should be `text-background-200`. | Before | After | |--------|--------| | <img width="371" height="67" alt="Screenshot 2026-07-14 at 16 46 42" src="https://github.com/user-attachments/assets/813ef5c8-98d1-4889-99b3-8bd885a48139" /> | <img width="366" height="64" alt="Screenshot 2026-07-14 at 16 47 53" src="https://github.com/user-attachments/assets/e76c120a-70c8-451a-a7a9-48814978cfd3" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the Info icon’s background-visible styling to use the correct background color for improved visual consistency. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7cffbcc47f | docs(cli): add local-dev workflow guide and restructure CLI docs (#47932) | ||
|
|
f0d2ae8e24 | docs: clarify Vault/pgsodium root key lifecycle and portability (#47876) | ||
|
|
3f2091395e | fix(billing): exit survey does not fire after downgrade via cancellation button (#47956) | ||
|
|
e218b24f96 |
fix(studio): disable unified logs on self-hosted (#47727)
## What Disable the Unified Logs feature on self-hosted Studio (`IS_PLATFORM=false`), where there is no backend to support it. Fixes [FE-3747](https://linear.app/supabase/issue/FE-3747). ## Why Unified logs is platform-only. A provider-level guard already forces the `isPlatformOnly` preview flag off on self-hosted, but two gaps let the feature still surface: 1. The logs sidebar renders `<UnifiedLogsBanner />` unconditionally, so self-hosted users saw an **"Enable preview"** button. Clicking it wrote the preview flag to local storage and routed to `/logs`, transiently rendering the unified logs UI. 2. `useUnifiedLogsPreview` derived `isDefaultOptIn` purely from the `unifiedLogsDefaultOptIn` feature flag, with no platform check. ## Changes - `UnifiedLogsBanner` returns `null` when `!IS_PLATFORM`, removing the only entry point to enable the preview on self-hosted. - `useUnifiedLogsPreview` gates both `isEnabled` and `isDefaultOptIn` on `IS_PLATFORM`, making the hook authoritative so no flag/local-storage state can enable unified logs on self-hosted. ## Tests - `FeaturePreviewContext.selfhosted.test.tsx` — the hook never reports unified logs as enabled or default-opt-in on self-hosted, even with the feature flags on. - `UnifiedLogsBanner.selfhosted.test.tsx` — the banner renders nothing on self-hosted. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Restricted Unified Logs preview and banner availability to supported platform environments. * Prevented unsupported environments from displaying the Unified Logs banner or opting in by default. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a23f80dd40 |
feat(studio): identify unified logs analytics queries (#47963)
## What Unified Logs fires several `logs.all.otel` requests on load (row list, chart, sidebar facet counts, single-facet counts) plus inspection queries, all with no identifier — indistinguishable in the network tab. Adds a leading `-- unified logs: <what>` SQL comment to each query builder so each request is identifiable at a glance: - row list - severity chart (with bucket function) - sidebar facet counts - single-facet counts (with facet name) - inspect single log by id - edge function console logs for execution ## Notes `--` comments run to end of line; queries are sent multi-line, so the comment doesn't swallow the SQL. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Diagnostics** * Added descriptive labels to generated log queries, making SQL statements easier to identify in logs and diagnostics. * Added labels for unified log listings, facet counts, sidebar counts, severity charts, individual log inspections, and related console logs. * **Bug Fixes** * No changes to filtering, grouping, query results, or log retrieval behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
320604d0e7 |
feat(studio): ship both upgrade CTA placements, remove A/B experiment (#47881)
## What Concludes the `upgradeCtaPlacement` experiment ([#45858](https://github.com/supabase/supabase/pull/45858)) by shipping **both** placements permanently and removing the A/B scaffolding. The experiment tested two upgrade-CTA placements against a control: - **`user_dropdown`** — an "Upgrade to Pro" button in the account/user dropdown - **`org_projects_list`** — a plan-usage card in the org project list Both moved paid conversion in the same direction over control with no activation downside, and they live on separate surfaces, so we're keeping both rather than picking one. ## Changes - **Remove the experiment machinery.** Deleted `useUpgradeCtaExperiment` (PostHog `upgradeCtaPlacement` flag read, `control` arm, variant selection, per-org localStorage seeding, exposure tracking) and replaced it with a small `useShowUpgradeCta` hook that gates purely on **free plan + hosted platform**. Both placements now render for every eligible free-plan org. - **Telemetry cleanup.** Removed the `upgrade_cta_placement_experiment_exposed` event (pure experiment scaffolding). Kept `upgrade_cta_clicked` (with its `placement` property) so we can still measure the CTAs going forward; de-experimented its wording. - **Dead code.** Removed the unused `prependCard` prop plumbing added to `ProjectList` / `EmptyStates` (no caller ever passed it — the org card renders via the `<aside>`). - De-experimented the remaining doc comments in `PlanUsageCard`. Gating is unchanged in spirit: paid orgs and self-hosted never see the CTA. `useShowUpgradeCta` waits until the org plan is known before returning true, so the CTA fades in for free users and never flashes for paid users. ## Testing - `pnpm --filter common typecheck` and `pnpm --filter studio typecheck` pass. - eslint + prettier clean on the changed files. - Manually checked <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Upgrade/usage CTAs now appear only when the organization is confirmed to be on a free plan, avoiding premature rendering before plan data is available. - Upgrade CTA visibility is now consistently driven across supported project and organization surfaces (including the user dropdown) for org-scoped routes. - **Bug Fixes** - Removed obsolete “prepend” placeholders from the project list loading and grid views to keep card layouts consistent. - **Documentation** - Clarified upgrade CTA telemetry wording and adjusted the frontend telemetry contract. - **Tests** - Added coverage for upgrade-CTA visibility behavior across key scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
92b8ba7cc9 |
fix(studio): give unified logs filter 'Only' button a solid background (#47953)
The "Only" button in the Unified Logs filter facets had no background, so it overlapped the label/count behind it on hover. Added a solid `bg-background`, set the label to 10px, and capitalized it to "Only". Applied to both the sync and async filter checkbox components. ## Before / After Button now sits on an opaque background and no longer bleeds into the row below. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved checkbox filter hover interactions by hiding count markers when hovering over an option. * Updated the “Only” control styling for clearer visibility, alignment, and hover behavior. * Capitalized the control label to “Only” for improved readability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
00f75b6cff |
fix(studio): bottom padding projects list (#47959)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? We had a rouge `pb-0` on the projects list eliminating the bottom padding when the list/scroll is long enough. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved spacing beneath the Projects page content for a more balanced layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d23f86021a |
feat(www): Partner Catalog update (#46757)
## Info architecture change around "Partners" The www "integrations" now become more partner-driven. `/partners/integrations` -> now Partner Catalog under `/partners/catalog` (old links redirect to new paths) Moved them close together in the nav dropdown and in the footer <img width="494" height="336" alt="Screenshot 2026-07-09 at 11 06 41" src="https://github.com/user-attachments/assets/a875fef0-0ab8-47ca-8756-d658b27c4892" /> <img width="1149" height="665" alt="Screenshot 2026-07-09 at 11 09 48" src="https://github.com/user-attachments/assets/9631bb72-fe25-4fb4-b1af-9f14a37d02e7" /> ## /partners This page remains untouched in this PR, updates to layout, content and intake form are delegated to #47874 ## /partners/catalog Listed in the [catalog](https://zone-www-dot-com-git-feat-www-partners-pages-supabase.vercel.app/partners/catalog) are now partners. Some partners match with a listing. <img width="1207" height="866" alt="Screenshot 2026-07-09 at 11 14 17" src="https://github.com/user-attachments/assets/b65216be-976f-4ef5-91f8-1ad49da87b45" /> ## /partners/catalog/[partner] Each partner can have one or more "listings" which are either - simple guides - foreign data wrappers - dashboard integrations Integrations available in the dashboard now all have a prominent "Install integration" cta to open it in the dashboard [integrations page](https://supabase.com/dashboard/project/_/integrations). <img width="1269" height="776" alt="Screenshot 2026-07-09 at 11 16 51" src="https://github.com/user-attachments/assets/3c7bb715-ffce-4d0a-905f-9a660c3b1f5a" /> ## Docs Update docs → [Preview](https://docs-git-feat-www-partners-pages-supabase.vercel.app/docs/guides/integrations) - remove "Supabase marketplace" - use "Dashboard Integrations and Partner Catalog - update integrations in sidenav to link to updated /partners/catalog/** listings <img width="1520" height="696" alt="Screenshot 2026-07-15 at 12 54 47" src="https://github.com/user-attachments/assets/9f5a2794-4536-4299-97df-9732d3d75b4c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Partner Catalog experience with search, category filters, official-partner toggle, responsive filtering (sidebar + bottom sheet), grid/list views, and featured partners. * Added Partner Catalog detail pages with tabbed listings, MDX-rendered content, image gallery with zoom overlay, and “add/install” actions. * **Improvements** * Updated “Become a Partner” layout and form support for prefilled values and checkbox-group fields (including validation). * Updated navigation/footer/docs and partner tile links to use Partner Catalog routes; expanded redirects from legacy integrations paths. * Added public agent-skills discovery manifest. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alan Daniel <stylesshjs@gmail.com> Co-authored-by: Alex Hall <alex.hall@supabase.io> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
1b1b1ea0e0 |
chore: remove dead telemetry code (#47950)
## Summary Removes two pieces of dead telemetry code found while root-causing the docs pageview re-fire investigation (GROWTH-997, closed with no fix needed). Pure deletion, 30 lines, no behavior change. ## Changes - Delete `apps/www/app/ConsentWrapper.tsx`: an unwired third `PageTelemetry` mount. www already mounts `PageTelemetry` in `pages/_app.tsx` (Pages Router) and `app/providers.tsx` (App Router); nothing imports this wrapper. - Remove the exported `POSTHOG_URL` constant from `apps/studio/lib/constants/index.ts`: zero consumers. The CSP allowlist in `apps/studio/csp.ts` defines and uses its own local `POSTHOG_URL`, which stays. ## Testing Deadness verified before deletion, on current master: - [x] Repo-wide grep for `ConsentWrapper`: only self-references inside the deleted file - [x] Repo-wide grep for `POSTHOG_URL`: remaining references are the `csp.ts` local const only ## Linear - fixes GROWTH-1002 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Removed an obsolete consent-related page wrapper to streamline page behavior. * Updated application configuration handling without changing existing payment or usage settings. * **Refactor** * Simplified internal configuration and page composition while preserving the existing user experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b02ad91319 |
fix(studio): stop unified logs bar chart animation replay on click FE-3912 (#47910)
## Problem In the unified logs dashboard, clicking an activity bar in the chart restarted the fly-by entrance animation instead of selecting that bar. There was also no way to select a single bar by clicking it (only drag-to-select worked), and the selection menu was centered over the selection rather than anchored to its start. ## Fix - Disabled Recharts' `isAnimationActive` on the stacked `Bar` elements so re-renders from selection state no longer replay the entrance animation. - Clicking a single bar now selects that bar's full time bucket and opens the "Filter logs to selected range" menu, the same as dragging across it. - The menu is anchored to the start (leftmost pixel) of the selection instead of the mouse release position. ## How to test - Open a project's unified logs page - Wait for the activity chart to finish its initial load - Click on a single bar - Expected result: the bar is highlighted, the chart does not replay its entrance animation, and the range-filter menu appears anchored at the start of that bar - Drag across multiple bars - Expected result: the range-filter menu appears anchored at the start of the dragged selection, not centered over it <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Fixed chart highlight popovers to anchor consistently to the start of the selected range. - Improved popover behavior so it updates correctly when the position changes. - Corrected zoom-in filtering when the selected range contains a single timestamp. - **UI Improvements** - Reduced conflicts between tooltips and selection popovers by rendering tooltip content only when appropriate. - Disabled stacked-bar animations for error/warning/success to make chart interactions feel steadier. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
66691ad9ce |
Joshen/fe 3384 prevent ai assistant chat panel from closing after query (#47951)
## Context 2 problems that this PR addresses - but these are in general due to the mobile UI behaviour - Sidebars (e.g Help Panel, Advisor Panel, etc) closes whenever there's a route change - This is happening because of `StudioMobileSheetNav`'s `handleOpenChange` interfering with the sidebar visible state - Am opting to not render `StudioMobileSheetNav` at all unless on mobile - On mobile, if you're on the Advisor Panel, clicking the "Menu" button closes the mobile sheet - Clicking on the Menu button seems to be triggering `MobileSheetNav`'s `onOpenChange` - My suspicion is because of state asymmetry between two independent stores (MobileSheetContext and SidebarManagerState - these 2 are a bit too complex imo) - Am opting to skip calling `onOpenChange` in `StudioMobileSheetNav` if the click target is within the Floating toolbar ## To test - [x] Desktop: Have the assistant panel open and change routes, panel should stay open - [x] Mobile: Open the assistant panel, then switch to the menu, panel should stay open <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved mobile navigation interactions so the navigation sheet remains open while toolbar actions are being selected. * Mobile navigation now displays only on smaller screens, preventing it from appearing at medium and larger breakpoints. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c9eb33abc7 | feat(pipelines): Add new cost estimation dialog (#47915) | ||
|
|
c97bc6282d |
Adjust AIAssistantHeader (#47912)
## Context As per PR title, just adjusting the Assistant's header a little to improve the UX ### Before <img width="442" height="71" alt="image" src="https://github.com/user-attachments/assets/c714e264-7724-451a-aeaf-7ced456d0639" /> ### After <img width="438" height="77" alt="image" src="https://github.com/user-attachments/assets/11467bf2-7306-4ec9-80e0-2aadd959eff1" /> ## Changes involved - Shift permission settings into "More" dropdown - Chat selection is now "history" - Added keyboard shortcuts for history and copy chat ID <img width="185" height="95" alt="image" src="https://github.com/user-attachments/assets/fc1c9bdc-9180-48ba-940f-2f39fef53a1d" /> <img width="287" height="159" alt="image" src="https://github.com/user-attachments/assets/8f597306-9ea0-4282-884b-722bab16e4d0" /> - Chat name is now clickable to directly edit it - Saves on Enter or on blur - Resets on Esc <img width="433" height="70" alt="image" src="https://github.com/user-attachments/assets/f0c6fb4a-c368-4722-97a2-22ae94cc5511" /> <img width="439" height="64" alt="image" src="https://github.com/user-attachments/assets/1eb21aaf-3979-433a-acc2-378b47b79e94" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added keyboard shortcuts to toggle the AI Assistant chat history and copy the active chat ID. * Added shortcut hint pills to AI Assistant tooltips and the “More options” menu. * Enabled inline editing of the active chat name with save/cancel and blur support. * **Improvements** * Refreshed AI Assistant header actions and icons (including “New chat” and menu controls) for clearer navigation. * Updated onboarding header styling with an assistant icon/animation. * Standardized shortcut rendering in tooltip pill formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fd5ec9fade |
Revert "feat: update @supabase/*-js libraries to v2.110.5" (#47918) (#47945)
Reverts #47918. ## Summary - Reverts `@supabase/auth-js`, `@supabase/postgrest-js`, `@supabase/realtime-js`, `@supabase/supabase-js` from 2.110.5 back to 2.110.1 in `pnpm-workspace.yaml` and `pnpm-lock.yaml`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated Supabase package versions to improve compatibility and consistency across the project. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
320c250106 |
Add Stephanie Jackson to humans.txt (#47937)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? I am not listed ## What is the new behavior? I am now listed! ## Additional context Onboarding task of course. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Stephanie Jackson to the team credits in the project’s public documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c8d60097d9 |
fix(docs): before-user-created hook had invalid ipnet cmp (#47940)
The comparison operator `<<` check if lhs is strictly contained by the rhs. Meaning a `/32` would return false for `/32` as the lhs is not contained, but equal to the rhs. The `<<=` is operator checks if a subnet is strictly contained or equal to which fixes the `/32` case. [1] https://www.postgresql.org/docs/17/functions-net.html#FUNCTIONS-NET <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the `before-user-created` hook SQL example to use the correct IP/CIDR containment syntax for both allow and deny network checks. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Chris Stockton <chris.stockton@supabase.io> |
||
|
|
52a25c2ebb |
refactor(sql-editor): extract AI/diff + shortcuts hooks (decompose 5/6) (#47935)
## What Decompose step **5 of 6** for `SQLEditor.tsx`. Extracts the Assistant / diff cluster and the keyboard-shortcut wiring out of the `SQLEditorContent` monolith into two focused, individually-testable hooks: - **`useSqlEditorAi`** — SQL completion (`complete`), the ask-AI prompt flow (`handlePrompt`), accept/discard diff handlers, `onDebug` / `buildDebugPrompt` helpers, `handleDiffEditorMount`, and the fragile diff lifecycle effects (one-shot diff-request drain, diff-editor value sync, ask-AI widget visibility). - **`useSqlEditorShortcuts`** — the registered shortcuts (focus editor, new snippet, format, explain) plus the accept/discard/escape keydown handling. `SQLEditorContent` now composes these hooks alongside the execution/explain hooks landed in decompose 4. ## Behavior-preserving This is a pure extraction. The moved function bodies, effect logic, dependency arrays, and JSX are unchanged from the previous monolith (verified via `git diff` against the pre-decomposition source). In particular: - `useEffectEvent` is preserved for `drainDiffRequest` / `resetDiff`. - `editorMountCount` remains single-owner (passed into the AI hook to drive the one-shot drain). - The untrusted→safe SQL promotion (`acceptUntrustedSql`) continues to happen in the run/explain gesture and warning-modal handlers in `SQLEditorContent`, as close to the explicit user action as possible. The Phase-1 characterization suite (`SQLEditor.test.tsx`, 11 tests) remains green. ## Stack Part of the SQLEditor decomposition stack (1/6 … 6/6). Builds on decompose 4 (execution + explain hooks, #47923). Next: PR6 splits the JSX into panes + final cleanup. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved SQL editor AI assistance, including completion prompts, debugging support, and diff review controls. * Added keyboard shortcuts for accepting or discarding AI-generated SQL changes. * Added shortcuts for focusing the editor, creating snippets, formatting queries, and explaining SQL. * **Bug Fixes** * Prevented SQL execution while reviewing AI-generated differences. * Improved handling of AI diff state during editor loading and interaction. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
05d2f38661 |
chore(deps): bump actions/github-script from 7.1.0 to 9.0.0 (#47929)
Bumps [actions/github-script](https://github.com/actions/github-script) from 7.1.0 to 9.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/github-script/releases">actions/github-script's releases</a>.</em></p> <blockquote> <h2>v9.0.0</h2> <p><strong>New features:</strong></p> <ul> <li><strong><code>getOctokit</code> factory function</strong> — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See <a href="https://github.com/actions/github-script#creating-additional-clients-with-getoctokit">Creating additional clients with <code>getOctokit</code></a> for details and examples.</li> <li><strong>Orchestration ID in user-agent</strong> — The <code>ACTIONS_ORCHESTRATION_ID</code> environment variable is automatically appended to the user-agent string for request tracing.</li> </ul> <p><strong>Breaking changes:</strong></p> <ul> <li><strong><code>require('@actions/github')</code> no longer works in scripts.</strong> The upgrade to <code>@actions/github</code> v9 (ESM-only) means <code>require('@actions/github')</code> will fail at runtime. If you previously used patterns like <code>const { getOctokit } = require('@actions/github')</code> to create secondary clients, use the new injected <code>getOctokit</code> function instead — it's available directly in the script context with no imports needed.</li> <li><code>getOctokit</code> is now an injected function parameter. Scripts that declare <code>const getOctokit = ...</code> or <code>let getOctokit = ...</code> will get a <code>SyntaxError</code> because JavaScript does not allow <code>const</code>/<code>let</code> redeclaration of function parameters. Use the injected <code>getOctokit</code> directly, or use <code>var getOctokit = ...</code> if you need to redeclare it.</li> <li>If your script accesses other <code>@actions/github</code> internals beyond the standard <code>github</code>/<code>octokit</code> client, you may need to update those references for v9 compatibility.</li> </ul> <h2>What's Changed</h2> <ul> <li>Add ACTIONS_ORCHESTRATION_ID to user-agent string by <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li> <li>ci: use deployment: false for integration test environments by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/712">actions/github-script#712</a></li> <li>feat!: add getOctokit to script context, upgrade <code>@actions/github</code> v9, <code>@octokit/core</code> v7, and related packages by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/700">actions/github-script#700</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Copilot"><code>@Copilot</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/github-script/compare/v8.0.0...v9.0.0">https://github.com/actions/github-script/compare/v8.0.0...v9.0.0</a></p> <h2>v8.0.0</h2> <h2>What's Changed</h2> <ul> <li>Update Node.js version support to 24.x by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/637">actions/github-script#637</a></li> <li>README for updating actions/github-script from v7 to v8 by <a href="https://github.com/sneha-krip"><code>@sneha-krip</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/653">actions/github-script#653</a></li> </ul> <h2>⚠️ Minimum Compatible Runner Version</h2> <p><strong>v2.327.1</strong><br /> <a href="https://github.com/actions/runner/releases/tag/v2.327.1">Release Notes</a></p> <p>Make sure your runner is updated to this version or newer to use this release.</p> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github-script/pull/637">actions/github-script#637</a></li> <li><a href="https://github.com/sneha-krip"><code>@sneha-krip</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github-script/pull/653">actions/github-script#653</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/github-script/compare/v7.1.0...v8.0.0">https://github.com/actions/github-script/compare/v7.1.0...v8.0.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/github-script/commit/3a2844b7e9c422d3c10d287c895573f7108da1b3"><code>3a2844b</code></a> Merge pull request <a href="https://redirect.github.com/actions/github-script/issues/700">#700</a> from actions/salmanmkc/expose-getoctokit + prepare re...</li> <li><a href="https://github.com/actions/github-script/commit/ca10bbdd1a7739de09e99a200c7a59f5d73a4079"><code>ca10bbd</code></a> fix: use <code>@octokit/core/</code>types import for v7 compatibility</li> <li><a href="https://github.com/actions/github-script/commit/86e48e20ac85c970ed1f96e718fd068173948b7b"><code>86e48e2</code></a> merge: incorporate main branch changes</li> <li><a href="https://github.com/actions/github-script/commit/c1084728b5b935ec4ddc1e4cee877b01797b3ff9"><code>c108472</code></a> chore: rebuild dist for v9 upgrade and getOctokit factory</li> <li><a href="https://github.com/actions/github-script/commit/afff112e4f8b57c718168af75b89ce00bc8d091d"><code>afff112</code></a> Merge pull request <a href="https://redirect.github.com/actions/github-script/issues/712">#712</a> from actions/salmanmkc/deployment-false + fix user-ag...</li> <li><a href="https://github.com/actions/github-script/commit/ff8117e5b78c415f814f39ad6998f424fee7b817"><code>ff8117e</code></a> ci: fix user-agent test to handle orchestration ID</li> <li><a href="https://github.com/actions/github-script/commit/81c6b7876079abe10ff715951c9fc7b3e1ab389d"><code>81c6b78</code></a> ci: use deployment: false to suppress deployment noise from integration tests</li> <li><a href="https://github.com/actions/github-script/commit/3953caf8858d318f37b6cc53a9f5708859b5a7b7"><code>3953caf</code></a> docs: update README examples from <a href="https://github.com/v8"><code>@v8</code></a> to <a href="https://github.com/v9"><code>@v9</code></a>, add getOctokit docs and v9 brea...</li> <li><a href="https://github.com/actions/github-script/commit/c17d55b90dcdb3d554d0027a6c180a7adc2daf78"><code>c17d55b</code></a> ci: add getOctokit integration test job</li> <li><a href="https://github.com/actions/github-script/commit/a047196d9a02fe92098771cafbb98c2f1814e408"><code>a047196</code></a> test: add getOctokit integration tests via callAsyncFunction</li> <li>Additional commits viewable in <a href="https://github.com/actions/github-script/compare/v7.1.0...3a2844b7e9c422d3c10d287c895573f7108da1b3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c9d7f00b8e |
feat(studio): add Go to API Keys command menu action (#47916)
## Summary - Add a "Go to API Keys" action under the command menu's Navigate section, linking to `/project/[ref]/settings/api-keys` ## Test plan - [ ] Open command menu, search "api key", confirm "Go to API Keys" navigates to the settings page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a command-menu option to quickly navigate to the project’s API Keys settings page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7a60819233 |
chore(deps): bump actions/checkout from 4.3.0 to 7.0.0 (#47925)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.3.0 to 7.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/releases">actions/checkout's releases</a>.</em></p> <blockquote> <h2>v7.0.0</h2> <h2>What's Changed</h2> <ul> <li>block checking out fork pr for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> <li>getting ready for checkout v7 release by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li> <li>update error wording by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p> <h2>v6.0.3</h2> <h2>What's Changed</h2> <ul> <li>Update changelog by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>Update changelog for v6.0.3 by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/yaananth"><code>@yaananth</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p> <h2>v6.0.2</h2> <h2>What's Changed</h2> <ul> <li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p> <h2>v6.0.1</h2> <h2>What's Changed</h2> <ul> <li>Update all references from v5 and v4 to v6 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> <li>Clarify v6 README by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p> <h2>v6.0.0</h2> <h2>What's Changed</h2> <ul> <li>Update README to include Node.js 24 support details and requirements by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li> <li>Persist creds to a separate file by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li> <li>v6-beta by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2298">actions/checkout#2298</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v7.0.0</h2> <ul> <li>Block checking out fork PR for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> </ul> <h2>v6.0.3</h2> <ul> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <h2>v6.0.2</h2> <ul> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <h2>v6.0.1</h2> <ul> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> </ul> <h2>v6.0.0</h2> <ul> <li>Persist creds to a separate file by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li> <li>Update README to include Node.js 24 support details and requirements by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li> </ul> <h2>v5.0.1</h2> <ul> <li>Port v6 cleanup to v5 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li> </ul> <h2>v5.0.0</h2> <ul> <li>Update actions checkout to use node 24 by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li> </ul> <h2>v4.3.1</h2> <ul> <li>Port v6 cleanup to v4 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li> </ul> <h2>v4.3.0</h2> <ul> <li>docs: update README.md by <a href="https://github.com/motss"><code>@motss</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li> <li>Add internal repos for checking out multiple repositories by <a href="https://github.com/mouismail"><code>@mouismail</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li> <li>Documentation update - add recommended permissions to Readme by <a href="https://github.com/benwells"><code>@benwells</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li> <li>Adjust positioning of user email note and permissions heading by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li> <li>Update README.md by <a href="https://github.com/nebuk89"><code>@nebuk89</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li> <li>Update CODEOWNERS for actions by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li> <li>Update package dependencies by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li> </ul> <h2>v4.2.2</h2> <ul> <li><code>url-helper.ts</code> now leverages well-known environment variables by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li> <li>Expand unit test coverage for <code>isGhes</code> by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li> </ul> <h2>v4.2.1</h2> <ul> <li>Check out other refs/* by commit if provided, fall back to ref by <a href="https://github.com/orhantoy"><code>@orhantoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a> update error wording (<a href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li> <li><a href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a> getting ready for checkout v7 release (<a href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a> Bump the minor-npm-dependencies group across 1 directory with 3 updates (<a href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li> <li><a href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a> upgrade module to esm and update dependencies (<a href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li> <li><a href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a> Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid (<a href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li> <li><a href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a> Bump js-yaml from 4.1.0 to 4.2.0 (<a href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li> <li><a href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a> Bump flatted from 3.3.1 to 3.4.2 (<a href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li> <li><a href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a> Bump actions/publish-immutable-action (<a href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a> block checking out fork pr for pull_request_target and workflow_run (<a href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li> <li><a href="https://github.com/actions/checkout/commit/df4cb1c069e1874edd31b4311f1884172cec0e10"><code>df4cb1c</code></a> Update changelog for v6.0.3 (<a href="https://redirect.github.com/actions/checkout/issues/2446">#2446</a>)</li> <li>Additional commits viewable in <a href="https://github.com/actions/checkout/compare/08eba0b27e820071cde6df949e0beb9ba4906955...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |
||
|
|
74c75c6d3a |
fix(studio): cap errors-since-last-deploy log range to 24h DEBUG-173 (#47911)
## Problem The edge function overview's "Errors since last deploy" panel queried ClickHouse from the deploy timestamp to now, with no upper bound. When a function had not been redeployed in a long time, this produced an unbounded query range, which is suspected to have caused a recent uptime incident. ## Fix `getSinceLastDeployLogRange` now clamps the query start to at most 24 hours before now, shared by all three queries this panel issues (invocation list, invocation count, runtime logs). The section title was also updated from "Errors since last deploy" to "Errors in the last 24h" to reflect the new bound. ## How to test - Open an edge function's overview page for a function that was deployed more than 24 hours ago - Confirm the "Errors in the last 24h" panel loads without an excessively large query range - Expected result: the panel only queries the last 24 hours of logs regardless of how old the last deploy was - Run `pnpm test:studio -- EdgeFunctionRecentErrors.utils` and confirm the range-clamping tests pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Updated the Edge Function errors section to show errors from the last 24 hours. - **Bug Fixes** - Limited error log searches to a maximum 24-hour window, preventing outdated results from appearing. - Improved handling of error time ranges when the last deployment occurred earlier than the available window. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b5ac80295e |
docs(skills): add copywriting skill (#47921)
## Problem Agents writing or auditing UI copy have no pointer to the existing copywriting guide in the design system, so copy conventions (voice, buttons, error messages, empty states) aren't consistently applied. ## Fix Add a `copywriting` skill file that points agents to `apps/design-system/content/docs/copywriting.mdx` before writing or reviewing any user-facing text. ## How to test - Ask an agent to write or review UI copy (e.g. a button label or error message) - Confirm it reads `apps/design-system/content/docs/copywriting.mdx` before responding <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for writing and reviewing user-facing interface copy. * Included a requirement to consult the designated copywriting documentation before publishing or reviewing text. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
88f3173920 |
Remove home page skeleton loader, improve base loading behaviour (#47903)
## Context The project's home page has been updated for a while now, but the skeleton loader is still showing the old layout Am opting to remove the skeleton loader entirely and instead improve the loading state of the base UI - adjusts some heights to minimize layout shifts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Added shimmer loading for project titles while project details are loading. * Refined project connection dropdown behavior: improved URL display/truncation, adjusted dropdown alignment, and more reliable option selection (disabled items remain unavailable). * Streamlined the project page’s loading and transition experience across different project states. * **Tests** * Updated the connect E2E scenario to interact with the Connect sheet via its accessible label before selecting the ORM option. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8b82d5c472 |
[FE-3895] fix(studio): fit unified logs table to mobile viewport (#47930)
The unified logs table has a fixed content width of ~1400px, so on mobile it overflowed the viewport — columns were clipped and the header appeared misaligned with the rows (the underlying columns were actually aligned; the table just didn't fit). **Changed:** - Progressively hide the three widest columns on narrow viewports via responsive display classes: `method` from `sm`, `pathname` from `md`, `event message` from `lg`. - On phones only the essential columns remain (checkbox, level, date, log type, status), so the table fits with no horizontal scroll. - Desktop (≥`lg`) is unchanged — all columns render exactly as before. Full row data (method/pathname/event message) is still accessible by clicking a row to open the detail panel. ## To test - Open a project's **Logs** (Unified Logs preview) at a mobile width (~390px), with some API log rows in range. - Confirm the table fits the screen — no horizontal scroll/clipping — and the `DATE` header sits cleanly above the dates. - Widen the browser: `method` appears ~640px, `pathname` ~768px, `event message` ~1024px. - At desktop width, confirm all columns show and header/rows line up as before. - Tap a row on mobile → detail panel opens with the full log (method, pathname, event message). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved responsive table layouts for unified logs. * Columns now adapt visibility based on screen size, keeping key information accessible on narrow displays. * Event messages flex more naturally when visible. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
e90c91e498 |
fix(studio): show custom OAuth providers in Users table (#45658)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? show provider info in Authentication -> Users page if user is auth'd with custom providers <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Added comprehensive support for custom authentication providers with appropriate type labeling and visual identification * Improved provider display formatting and icon rendering to properly recognize custom authentication options * Enhanced authentication provider interface operations for better custom provider information handling and management <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
3ed7c8f522 |
feat: update @supabase/*-js libraries to v2.110.5 (#47918)
This PR updates @supabase/*-js libraries to version 2.110.5. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.5 - Updated @supabase/auth-js to 2.110.5 - Updated @supabase/realtime-js to 2.110.5 - Updated @supabase/postgest-js to 2.110.5 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](https://github.com/supabase/supabase-js/pull/2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](https://github.com/supabase/supabase-js/pull/2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](https://github.com/supabase/supabase-js/pull/2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique ## v2.110.3 ## 2.110.3 (2026-07-13) ### 🩹 Fixes - **auth:** preserve pkce verifier ([#2513](https://github.com/supabase/supabase-js/pull/2513)) - **postgrest:** pin tstyche target off floating latest ([#2509](https://github.com/supabase/supabase-js/pull/2509)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp ## v2.110.2 ## 2.110.2 (2026-07-09) ### 🩹 Fixes - **auth:** clear local session on signout failures ([#2504](https://github.com/supabase/supabase-js/pull/2504)) ### ❤️ Thank You - Luc Peng This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
7832d9f716 |
chore: dependabot autobump gha major versions (#47924)
We were ignoring major version updates for Dependabot updates of GitHub Actions, so we are now several major versions behind on several actions. Turning major version updates back on so we can update everything. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Dependency update configuration now includes major version updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3fa7f086df |
refactor(sql-editor): extract execution + explain hooks (decompose 4/6) (#47923)
## Summary PR **4 of 6** in the SQLEditor decomposition stack. Extracts the two query-run concerns out of the composition root into cohesive hooks. Behavior-preserving — the characterization suite stays green. ## New hooks - `useSqlEditorExecution` — the execute mutation, the `executeQuery` pipeline (destructive-query gating, lazy title generation, connection resolution), and the `potentialIssues` warning-modal state. - `useSqlEditorExplain` — the execute-explain mutation and the `executeExplainQuery` pipeline. Both pipelines accept an **already-promoted `SafeSqlFragment`**. ## Safe-SQL boundary Per review guidance, `acceptUntrustedSql` promotion stays in the **composition root's** run/explain gesture handlers and warning-modal confirm handlers — as close to the explicit user action as possible, so it's auditable. The hooks never call `acceptUntrustedSql`; they only accept safe SQL. `executeQuery` lists its (now all-stable) dependencies directly rather than suppressing `react-hooks/exhaustive-deps`. ## Verification - `vitest` — 11 characterization tests pass - `pnpm --filter studio typecheck` — clean for SQL editor files - `eslint` / `lint:ratchet` — pass (0 new violations) - `prettier --check` — clean `SQLEditorContent` is down to ~530 lines (from 1056 at the start of the stack). Remaining: PR5 (AI/diff + shortcuts), PR6 (JSX pane split + cleanup). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL query execution safeguards for potentially destructive statements, unsafe updates, and missing row-level security coverage. * Improved EXPLAIN handling, including clearer validation for unsupported multi-statement queries. * Preserved query results, errors, and EXPLAIN output more reliably in the SQL editor. * **Improvements** * Added clearer execution status handling and more consistent editor focus, highlighting, and utility-tab behavior. * Improved connection selection and SQL execution reliability across supported database configurations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3870172108 |
chore(deps): bump akhilerm/tag-push-action from 2.1.0 to 2.3.0 (#47170)
Bumps [akhilerm/tag-push-action](https://github.com/akhilerm/tag-push-action) from 2.1.0 to 2.3.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/akhilerm/tag-push-action/releases">akhilerm/tag-push-action's releases</a>.</em></p> <blockquote> <h2>v2.3.0</h2> <h3>Highlights</h3> <ul> <li>The action now runs on the Node 24 runtime.</li> </ul> <h3>What's Changed</h3> <ul> <li>internal split into <code>src/index.ts</code> / <code>src/main.ts</code> for cleaner testing.</li> <li>Dependency updates: <ul> <li>Bump typescript from 4.8.4 to 4.9.5 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/363">akhilerm/tag-push-action#363</a></li> <li>Bump actions/checkout from 4 to 6 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/375">akhilerm/tag-push-action#375</a></li> <li>Bump prettier from 3.1.0 to 3.8.4 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/376">akhilerm/tag-push-action#376</a>, <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/385">akhilerm/tag-push-action#385</a></li> <li>Bump <code>@types/node</code> from 20.10.5 to 25.9.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/377">akhilerm/tag-push-action#377</a></li> <li>Bump csv-parse from 5.3.1 to 6.2.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/378">akhilerm/tag-push-action#378</a></li> <li>Bump <code>@vercel/ncc</code> from 0.34.0 to 0.44.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/379">akhilerm/tag-push-action#379</a>, <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/390">akhilerm/tag-push-action#390</a></li> <li>Bump docker/login-action from 1 to 4 by <a href="https://github.com/akhilerm"><code>@akhilerm</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/380">akhilerm/tag-push-action#380</a></li> <li>Bump ts-jest from 27.1.5 to 29.4.11 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/382">akhilerm/tag-push-action#382</a></li> <li>Bump eslint-plugin-prettier from 5.1.2 to 5.5.6 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/383">akhilerm/tag-push-action#383</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/384">akhilerm/tag-push-action#384</a></li> <li>Bump eslint-plugin-github from 4.4.1 to 6.0.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/386">akhilerm/tag-push-action#386</a></li> <li>Bump jest-circus from 29.7.0 to 30.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/389">akhilerm/tag-push-action#389</a></li> <li>Bump eslint-plugin-jest from 27.9.0 to 29.15.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/391">akhilerm/tag-push-action#391</a></li> <li>Bump jest and <code>@types/jest</code> by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/392">akhilerm/tag-push-action#392</a></li> </ul> </li> </ul> <h3>CI / testing</h3> <ul> <li>Added a self-contained copy test against a local authenticated registry.</li> <li>Moved the live docker.io <> quay.io copy test to a daily scheduled run</li> </ul> <p><strong>Full changelog</strong>: <a href="https://github.com/akhilerm/tag-push-action/compare/v2.2.0...v2.3.0">https://github.com/akhilerm/tag-push-action/compare/v2.2.0...v2.3.0</a></p> <h2>v2.2.0</h2> <h2>Highlights</h2> <ul> <li>update to nodejs 20</li> </ul> <h2>What's Changed</h2> <ul> <li>Bump prettier from 2.4.1 to 3.1.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/343">akhilerm/tag-push-action#343</a></li> <li>Bump jest-circus from 27.5.1 to 29.7.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/320">akhilerm/tag-push-action#320</a></li> <li>Bump eslint-plugin-jest from 27.1.4 to 27.6.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/340">akhilerm/tag-push-action#340</a></li> <li>Bump json5 from 1.0.1 to 1.0.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/296">akhilerm/tag-push-action#296</a></li> <li>Bump <code>@actions/core</code> from 1.10.0 to 1.10.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/345">akhilerm/tag-push-action#345</a></li> <li>Bump <code>@typescript-eslint/parser</code> from 5.42.1 to 5.62.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/347">akhilerm/tag-push-action#347</a></li> <li>Bump eslint-plugin-prettier from 4.2.1 to 5.1.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/358">akhilerm/tag-push-action#358</a></li> <li>Bump <code>@types/node</code> from 16.18.3 to 20.10.5 by <a href="https://github.com/dependabot"><code>@dependabot</code></a> in <a href="https://redirect.github.com/akhilerm/tag-push-action/pull/355">akhilerm/tag-push-action#355</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/akhilerm/tag-push-action/compare/v2.1.0...v2.2.0">https://github.com/akhilerm/tag-push-action/compare/v2.1.0...v2.2.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/akhilerm/tag-push-action/commit/eadeefebd39db8a47e146115649adae1fce576a6"><code>eadeefe</code></a> Merge pull request <a href="https://redirect.github.com/akhilerm/tag-push-action/issues/389">#389</a> from akhilerm/dependabot/npm_and_yarn/jest-circus-30.4.2</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/8962cb7144ecbebc290b74473bf46cd306a7c3e6"><code>8962cb7</code></a> Bump jest-circus from 29.7.0 to 30.4.2</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/28c3d7f674c6db27447b68e235def041eb57d98f"><code>28c3d7f</code></a> Merge pull request <a href="https://redirect.github.com/akhilerm/tag-push-action/issues/390">#390</a> from akhilerm/dependabot/npm_and_yarn/vercel/ncc-0.44.0</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/0ecaec2cfa9c7db7258779fd5689f2aaca86e883"><code>0ecaec2</code></a> Merge pull request <a href="https://redirect.github.com/akhilerm/tag-push-action/issues/391">#391</a> from akhilerm/dependabot/npm_and_yarn/eslint-plugin-j...</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/c248b0c1347994c44123a0dd79038b7aff8e2ff4"><code>c248b0c</code></a> Merge pull request <a href="https://redirect.github.com/akhilerm/tag-push-action/issues/392">#392</a> from akhilerm/dependabot/npm_and_yarn/multi-cbfe5253e3</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/d702ee054d313a39442246aed022e4adb489b2ec"><code>d702ee0</code></a> Merge pull request <a href="https://redirect.github.com/akhilerm/tag-push-action/issues/393">#393</a> from akhilerm/fix-verify-multiarch-digest</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/efcee5718416156e4ea7f854462c3ef28586c657"><code>efcee57</code></a> Verify registry digests instead of local image IDs</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/a5909e03cedeca22f40bb94923903a064d0cf3a7"><code>a5909e0</code></a> Bump jest and <code>@types/jest</code></li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/231bdfa4f4c073bd7232c802ccc27167f99ad87b"><code>231bdfa</code></a> Bump eslint-plugin-jest from 27.9.0 to 29.15.2</li> <li><a href="https://github.com/akhilerm/tag-push-action/commit/d15340e5e7ed46fa81242241a38bd6a0bbc463cd"><code>d15340e</code></a> Bump <code>@vercel/ncc</code> from 0.38.4 to 0.44.0</li> <li>Additional commits viewable in <a href="https://github.com/akhilerm/tag-push-action/compare/85bf542f43f5f2060ef76262a67ee3607cb6db37...eadeefebd39db8a47e146115649adae1fce576a6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |
||
|
|
03e6ef7f84 |
docs(telemetry): correct @page docs for branch-delete and sql autosave-disable events (#47922)
<!-- ccr-slack-attribution --> _Requested by **Pam Chia** · [Slack thread](https://supabase.slack.com/archives/C076KTY11DF/p1783905235047469)_ ## What kind of change does this PR introduce? Docs update (JSDoc comments only in the telemetry catalog — no runtime code, event names, or property types change). ## What is the current behavior? In `packages/common/telemetry-constants.ts`: - **Before:** The catalog only documented branch deletion as happening from the branches page. `branch_delete_button_clicked` listed a single `@page` of `/dashboard/project/{ref}/branches`, even though the button also fires from the merge page and from project Settings > General. - The `sql_editor_autosave_disable_clicked` event's `@page` read `/project/{ref}/sql/{id}`, missing the `/dashboard` prefix used by every sibling SQL-editor event. ## What is the new behavior? - **After:** `branch_delete_button_clicked` now documents all three surfaces where the button fires — the branches page, the merge page, and project Settings > General (`/dashboard/project/{ref}/branches, /dashboard/project/{ref}/merge or /dashboard/project/{ref}/settings/general`). - `sql_editor_autosave_disable_clicked` now uses `/dashboard/project/{ref}/sql/{id}`, consistent with the other SQL-editor events. ## Additional context **How:** Both changes are `@page` JSDoc edits in `packages/common/telemetry-constants.ts`, touching the JSDoc blocks for `BranchDeleteButtonClickedEvent` and `SqlEditorAutosaveDisableClickedEvent`. The multi-page format mirrors the comma/"or" style already used by other multi-page events in the same file. The Settings > General call site was added in #47677 (`apps/studio/components/interfaces/Settings/General/DeleteBranchPanel.tsx`); the merge-page and branches-page call sites are in `apps/studio/pages/project/[ref]/merge.tsx` and `apps/studio/pages/project/[ref]/branches/index.tsx`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_012mb6VWEpgrDYhgi7eyRpco --- _Generated by [Claude Code](https://claude.ai/code/session_012mb6VWEpgrDYhgi7eyRpco)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4096267623 |
feat(api-keys): migrate last-used indicator to ClickHouse endpoint (#47458)
## Problem The "last used" indicator for the legacy `anon` / `service_role` API keys (Project API keys settings) was disabled because it ran a BigQuery `edge_logs` query. It is now re-enabled against the ClickHouse-backed `api_keys.last_used.otel` analytics endpoint. ## Current behavior - The `anon` / `service_role` "last used" indicator is off (the BigQuery-backed query was disabled). ## New behavior - New `useApiKeysLastUsedQuery` hook calls the `api_keys.last_used.otel` endpoint (timestamp params only, no SQL sent), plus its query key and the generated platform API type. - `DisplayApiSettings` reads last-used from this hook instead of posting BigQuery `edge_logs` SQL. The pure `getLastUsedAPIKeys` shaper is kept and unit-tested. Still gated by the `showApiKeysLastUsed` flag. - Removed the disabled secret-keys (`sb_secret_`) BigQuery last-used path, which has no ClickHouse endpoint to migrate to: drops the dead `useLastSeen` query, the `APIKeyRow` "Last Used" column, and the unused `showLastSeen` prop. - Reworded the delete-confirmation copy to be accurate for both secret and publishable keys. ## Additional context - Backed by the platform endpoint in supabase/platform#34892 (merged and deployed). - Scope: `anon` / `service_role` legacy keys. Secret/publishable and JWT signing-key "last used" are follow-ups, pending the endpoint returning those key types. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated API key settings to show “last used” activity for the past 24 hours using a dedicated data source and time window. * Added clearer messaging when recent API key activity fails to load. * Removed the “Last Used” column from API key management tables. * **Bug Fixes** * Improved mapping so “last used” values correctly match the intended key and role. * Updated API key deletion confirmation to explain required backend changes and resulting unauthorized behavior. * **Tests** * Added unit tests to validate “last used” computation and edge-case filtering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
768ea1001b |
fix(studio): scope table editor introspection CTEs to target table OID (#47894)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (performance), plus a regression-guard test suite and docs. ## What is the current behavior? Studio's introspection queries in `@supabase/pg-meta` do `O(catalog)` work for per-table requests. On databases with very large catalogs (hundreds of thousands of relations/constraints — real deployments reach this) they take tens of seconds per dashboard interaction, trip `statement_timeout`, and create heavy CPU/memory pressure when several tabs open concurrently. Two instances of the same bug class: **1. Table Editor query (`getTableEditorSql`)** — fetches metadata for ONE table by OID, but five catalog scans are unscoped and only filtered at the top-level join: - `primary_keys` CTE — scans all of `pg_index` (`where i.indisprimary`) - `index_cols` CTE — scans all unique indexes - `relationships` CTE — scans every FK in `pg_constraint` (and is scanned twice by the two subplans) - `uniques` subquery (inside `columns`) — scans all single-column unique constraints - `check_constraints` subquery (inside `columns`) — scans all single-column check constraints The planner cannot push the outer join qual into grouped / `distinct on` subqueries, so each is computed over the full catalog and thrown away. `tables-paginated.ts` was previously rewritten to avoid exactly this pattern; the single-table query never got the same treatment. **2. Entity definitions (`getTableDefinitionSql` / `getEntityDefinitionsSql`)** — the vendored `pg_get_tabledef` plpgsql function scans the entire `information_schema.columns` view once **per column** (plus `information_schema.tables` once per call) just to decide whether a name needs double-quoting — a pure string property of a name it already holds — and its per-index partial-index lookup casts `relnamespace::regnamespace::text` across every `pg_class` row. On a 12K-table catalog this makes a single entity's DDL cost ~3.7s and a default 100-entity definitions page ~6 minutes. ## What is the new behavior? **Fix 1 — scope the Table Editor CTEs to the requested OID** (`id` is validated non-null and interpolated via `literal()`, same as the existing `base_table_info` filter): - `primary_keys` / `index_cols`: `and i.indrelid = <id>` - `relationships`: `and (c.conrelid = <id> or c.confrelid = <id>)` - `uniques` / `check_constraints`: `and conrelid = <id>` Semantics are unchanged: the top-level select already filtered every CTE to the target table, so rows for other tables were computed and discarded. The `pg_index`/`pg_constraint` lookups become index scans returning a handful of rows. One residual scan is structural: PostgreSQL has no index on `pg_constraint.confrelid`, so the incoming-FK half of `relationships` is a single filtered seq scan of `pg_constraint` — still one cheap pass instead of materializing every FK row twice. **Fix 2 — remove the O(catalog) scans inside `pg_get_tabledef`**: the information_schema uppercase checks are replaced with direct regex tests on the name in hand (preserving the original's `quote_ident` behavior for schemas that need quoting), and the partial-index lookup is scoped by the already-resolved table OID. Original statements are kept as comments, matching the vendored file's convention. **Regression guard** — so this bug class stays out: - `test/db/stress-catalog.ts` builds a synthetic catalog (default 2,000 tables with PKs, unique + check constraints, FK chains and an FK hub; `PG_META_STRESS_TABLES` scales it to incident size). - `test/db/plan-guard.ts` provides `EXPLAIN (ANALYZE, FORMAT JSON)`-based budget assertions: a query's plan may only seq-scan a scaling catalog if its budget entry carries a written structural justification (e.g. no index on `pg_constraint.confrelid`; no index on `pg_class.relnamespace` for per-schema listings), plus a per-query time bound (the only guard available for opaque plpgsql internals like `pg_get_tabledef`). - `test/sql/studio/catalog-plan-guard.test.ts` applies budgets to the hot-path studio queries: table editor, constraints, FK listing, entity types, tables-paginated, columns, indexes, table/entity definitions, views. Reverting either fix makes the suite fail immediately with the offending scans listed. - `test/sql/studio/table-editor.test.ts` (new — none existed) asserts the Table Editor query's semantics: primary keys, unique indexes, both FK directions, `is_unique`, check definitions, column comments. - A new package `README.md` documents the plan-guard budget entry as a requirement for any new introspection query. ### Validation (synthetic 12,000-table catalog, PostgreSQL 17.6) - **Output equivalence, fix 1:** for 12 relation types (regular, composite PK, partitioned parent + partition, view, materialized view, constraint-free table, FK hub/chain/tail, and a fixture with enums/domains/generated/identity columns and duplicate check constraints), the `entity` jsonb from the old and new query is byte-identical. - **Output equivalence, fix 2:** byte-identical DDL across 13 fixture combinations (serial/identity/generated/array columns, case-sensitive and keyword names, mixed-case schemas, partitions, unlogged + reloptions, partial/expression indexes, external PK/FK/comments/trigger variants). - **Performance, fix 1:** Table Editor query `EXPLAIN ANALYZE` ~1,630ms → ~30ms (~50×); the gap grows with catalog size since the old query is O(catalog) per call. - **Performance, fix 2:** single entity definition 3,672ms → 63ms; a 100-entity definitions page ~6min → 0.87s. The plan-guard bound for `getEntityDefinitionsSql` tightens accordingly from 15s/25 entities to 3s/100 entities (330ms measured at default test scale). Verified locally: `catalog-plan-guard` (12 tests), `table-editor`, `tables-paginated` (16 tests) pass; `typecheck` clean. ### Rollout Per review, the new behavior ships **dark** behind the `pgMetaScopedIntrospection` ConfigCat flag (default off = legacy SQL, kept as full duplicated templates in pg-meta and verified byte-identical to the pre-PR queries). Studio reads the flag in the query hooks and threads it through (flag state is part of the React Query keys). The rollout is staged in the ConfigCat dashboard via user-email targeting (like every other ConfigCat flag): target the reporting user's email first, then a percentage rollout, then 100%. Server-side AI callers of `getEntityDefinitionsSql` stay on the legacy path. Once fully rolled out, delete the legacy templates + flag in a cleanup PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Closes: PGMETA-122 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved table editor SQL to correctly scope primary keys, indexes, uniques, checks, and relationships to the selected table. - Optimized table definition SQL to reduce unnecessary catalog scanning for uppercase-name detection and partial-index detection. - **Tests** - Added SQL generator tests for table editor metadata (keys, indexes, relationships, comments, and constraints). - Added catalog query plan guard coverage with a stress catalog and EXPLAIN-based scoping/performance budgets. - **Documentation** - Expanded documentation on catalog query plan safeguards and how to keep new introspection queries properly scoped. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
b84aafd1a6 |
fix(ui-patterns): fix chart y-axis label clipping (#47890)
## Summary - Chart y-axis tick labels were clipped (e.g. edge function overview execution time charts) because `chart-line.tsx`/`chart-bar.tsx` hardcoded a `-40` left margin regardless of the actual `YAxisProps.width` passed in. - Margin now scales with the configured axis width. ## Test plan - [ ] Visually check edge function overview performance/usage charts render full tick labels (e.g. "195ms" instead of "ms") <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved chart layout and alignment across line and bar charts. - Adjusted Y-axis spacing so labels display more consistently when axes are shown or hidden. - Removed unnecessary fixed spacing from Edge Function performance, CPU, and memory charts. - Tightened spacing around chart timestamp rows for a more compact presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
06aafe4e0a |
Skip fetchAgentSkills for www typecheck GHA (#47907)
### Context Our TS check GHA occasionally runs into GH rate limits because of `fetchAgentSkills` ### Changes involved - Opting to omit `fetchAgentSkills` for typecheck - `generateStaticContent` is needed still afaict - Allow GITHUB_TOKEN to be passed for `generateStaticContent` - And pass that env var from `typecheck.yml` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **Improvements** - Enhanced reliability of GitHub-powered content during site builds. - GitHub API requests now use secure authentication when a token is available, improving consistency and reducing rate-limit risk. - Repository star and agent-skill loading continues to work gracefully without token access. - **Chores** - Streamlined the type-check workflow to use a leaner content build before running TypeScript checks. - Passed the GitHub token through relevant CI task environments to enable authenticated requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
+4 |
503bdb5a6f |
Fix filter button in table editor (#47867)
## Context Realised that the filter button in the table editor is broken so this PR fixes it <img width="385" height="393" alt="image" src="https://github.com/user-attachments/assets/94332f1b-cd69-4a8c-a822-3b9096d06ee3" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated the entity-type filter to use a clearer, labeled “Filter entity types” button with revised popover trigger and sizing. * Refreshed the table header filter controls, including the entity-type dropdown behavior and updated styling when filters are applied. * Improved handling when no entity types are currently visible by showing a dedicated empty-state within the filter menu. * **New Features** * Added a “No results based on filters” empty panel with a “Reset filters” action to restore all entity types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <alaister@users.noreply.github.com> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: kanad <github@kanad.dev> Co-authored-by: supabase-supabase-autofixer[bot] <248690971+supabase-supabase-autofixer[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> Co-authored-by: David_C <110653663+YuDavidCao@users.noreply.github.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> Co-authored-by: Nik Richers <nrichers@gmail.com> Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
00ecb53059 |
feat(etl): ETL usage insights+pricing docs (#47873)
Adds pipeline usage insights to summary and daily breakdowns + usage billing docs |
||
|
|
99d064e754 |
fix(www): add missing partner slug redirects (#47901)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Partner slugs were renamed from underscores to hyphens, but the redirect map only got partially updated. #46264 added entries for `refine_dev` and `supabase_wrapper_stripe`. Four others were missed and still hard 404, even though their replacement pages are live: | 404s today | Replacement page (200) | |---|---| | `/partners/integrations/atomic_crm` | `/partners/integrations/atomic-crm` | | `/partners/integrations/sequin_io` | `/partners/integrations/sequin` | | `/partners/integrations/supabase_wrapper_bigquery` | `/partners/integrations/bigquery-wrapper` | | `/partners/integrations/supabase_wrapper_firebase` | `/partners/integrations/firebase-wrapper` | These are the URLs Google has indexed and that external sites link to, so that traffic lands on an error page instead of the partner. Roughly 1.3k pageviews/month. Worth flagging for the reviewer: partner slugs come from the database, not the codebase, so renaming one doesn't force a matching redirect entry and nothing catches it at build time. This will happen again. ## What is the new behavior? Four `permanent: true` redirects added to `apps/www/lib/redirects.js`, matching the two that already exist in the partners block. ## Additional context Found while [digging into a decline in /partners traffic](https://supabase.slack.com/archives/C0161K73J1J/p1783931237132339). This accounts for ~7% of that decline — the rest is happening on healthy, indexed pages and is a separate question. Not included here: a few partner URLs 404 with no replacement page (`getstream_io`, `fezto`, `trevor_io`, `zapp_run`) — those partners look genuinely gone. Pointing them at `/partners/integrations` would hold onto more link equity than a hard 404, but that's a product call rather than a bug fix. Happy to add if people want it. Verified each old URL currently 404s and each destination returns 200. No duplicate `source` entries introduced. Prettier passes. |
||
|
|
7f8fb85caf |
Joshen/fe 3879 schema not exposed warning is unnecessarily repeated in (#47868)
Just a tiny nit i came across - realised that if the schema is not exposed via the API, the warning that we show on the policies page RE data not being selectable is repeated for each table which imo seems unnecessary. Opting for a single admonition at the top instead ## Before <img width="1085" height="744" alt="image" src="https://github.com/user-attachments/assets/7bd8cf7b-f5a8-47d6-b41f-13fc4782ed8b" /> ### After <img width="1080" height="673" alt="image" src="https://github.com/user-attachments/assets/c839f502-42ff-4184-ad07-0ff2fd2d2676" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an on-screen warning for tables whose schemas aren’t exposed via the project Data APIs, including a link to Data API settings. * **UI Improvements** * Refined the “filter entity types” control’s tooltip behavior and updated the popover header text. * **Bug Fixes** * Improved Data API/RLS status messaging by removing the prior “schema not exposed” outcome and showing “unknown” when access can’t be determined. * Consolidated policy warning rendering to avoid duplicated or inconsistent messages. * **Tests** * Updated policy/admonition helper tests to match the revised status and message behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c793352036 |
Add some keyboard shortcuts for the Assistant (#47872)
## Context Part of some minor improvements to the AI Assistant - this one's about adding some keyboard shortcuts ## Changes involved - Added keyboard shortcut for "New chat" <img width="212" height="96" alt="image" src="https://github.com/user-attachments/assets/e9c3bd63-adbc-4b05-8c52-1baed67e365a" /> - Also added a small animation for the "How can I assist you?" text for visual indication when moving between chats that might not have a conversation yet - Added keyboard shortcut for "Permission settings" <img width="236" height="86" alt="image" src="https://github.com/user-attachments/assets/337da009-5979-4910-9292-73cc4d7f7cce" /> - Show keyboard shortcut for "Close Assistant" <img width="165" height="88" alt="image" src="https://github.com/user-attachments/assets/b45a4f5a-8e12-45f1-8fdb-a18c0deedb02" /> - Fix `ExpandingTextArea` height calculation logic issue - If you open and close the Assistant panel a number of times, the height of the input field isn't consistent, so this fixes that <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Added keyboard shortcuts for starting a new AI Assistant chat and opening permission settings. - Header actions now display shortcut hints and support keyboard access. - **Improvements** - Enhanced accessibility with labels for chat edit controls (save, cancel, edit, delete). - Chat onboarding now remounts when switching active chats. - Improved chat popover alignment. - Escape now blurs the message input; textarea resizing is more reliable during content/layout changes. - **Bug Fixes** - Updated onboarding loading behavior based on the lints loading state. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6418820b0b |
docs: convert self-hosting overview to ContentListings and restructure the page (#47469)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This PR converts link sections in the self-hosting overview page to the `ContentListings` component, puts conceptual guidance before deployment options, and adds badge support for the Docker card (minor). Relates to DOCS-1137 ## Current behavior `self-hosting.mdx` uses hand-authored `<GlassPanel>` / `<Link>` JSX for two sections: - **Get started**: Docker card with a JSX title containing a `<Badge>` element (was previously deferred for this reason). - **Community-driven projects**: Two cards with trivial `<span>`-wrapped string titles. Get started and Community cards appear at the top of the page, before the conceptual overview. The Support and community section uses hand-authored bullet lists for GitHub, Discord, and Reddit links. ## New behavior - The self-hosting overview page now uses data-driven `ContentListings` instead of hand-written cards and bullet lists. - Conceptual content (how self-hosting differs, your responsibilities, telemetry) comes first; deployment options and community resources follow. - Section intro text lives in listing data rather than inline MDX. - Brand icons added to all listing cards (Docker, Kubernetes, Traefik, GitHub, Discord, Reddit). - Minor: Added support for badges to content listings, such as "Official" in the Docker tile Data lives in `self-hosting.data.ts` (5 groups, 8 links) and is registered in `content-listings/index.ts`. ## Additional context ### Icon usage rights New brand icons (Kubernetes, Traefik, Reddit) are sourced from [Simple Icons](https://simpleicons.org) (CC0 1.0). Existing icons (Docker, GitHub, Discord) reuse assets already in `apps/docs/public/img/icons/`. Use is non-commercial documentation only — consistent with existing docs icon usage and trademark fair-use for identifying linked third-party services. ### To do: - [ ] Check with @aantti if he's on board with switching the page to content listings we can lint for and the content restructure to match other overview pages ## Verification | Gate | Result | |------|--------| | `pnpm vitest run lib/content-listings.test.ts` | ✅ 12/12 passed | | `pnpm build:guides-markdown` | ✅ 744 files generated | | `pnpm lint:mdx` (self-hosting.mdx) | ✅ No warnings on changed file | ### Proof: restructured self-hosting page with ContentListings and icons | [Before (production)](https://supabase.com/docs/guides/self-hosting) | [After (PR preview)](https://docs-git-nikrichers-docs-1137-self-hosting-supabase.vercel.app/docs/guides/self-hosting) | |---|---| |  |  | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the self-hosting guide to use dynamic content listings for “Get started,” community resources, support options, and sharing experiences. * Added richer listing cards with optional badges and improved icon handling. * Expanded self-hosting resource groups to surface more relevant links in docs navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
a9115b694f |
fix(docs) Prevent dashboard links from breaking (#47897)
Closes DOCS-1174 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem Links from docs to studio can break. There's no way to programmatically check. ## Solution Add a unit test to check that `/dashboard` relative links from docs is absolute. ## Testing 1. Pull this branch to your local machine. 1. Break the link in `apps/docs/data/content-listings/database.data.ts` — change: `href: 'https://supabase.com/dashboard/project/_/sql',` to: `href: '/dashboard/project/_/sql',` 1. Run: cd `apps/docs && pnpm exec vitest run lib/content-listings.test.ts`. You should see dashboard content listing hrefs fail. Restore the absolute URL when you’re done. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added validation to ensure dashboard links in documentation content listings use complete, canonical URLs. * Added coverage for identifying dashboard links across all content listing groups. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
da724eb8c6 |
ci: add zizmor lint and harden GitHub Actions workflows (#47895)
## Summary - Add a zizmor config and CI job that lints `.github/workflows` on every PR touching it, downloading and attestation-verifying the pinned v1.26.1 release binary (cached across runs) - Fix the mutable-tag and excess-permission findings zizmor surfaces in `braintrust-evals.yml`, `publish_image.yml`, and `self-host-tests-smoke.yml`: pin `actions/checkout`/`actions/setup-node` to commit SHAs, and scope `pull-requests`/`packages`/`id-token` permissions down to the specific jobs that need them ## Test plan - [x] Confirm the `zizmor` job runs and passes on this PR <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added automated security scanning for workflow changes on pull requests. * Added configuration to allow specific workflow trigger exceptions. * **Security** * Tightened GitHub Actions permissions at the workflow level and re-granted only where required per job. * Pinned common build action versions to specific commits for more consistent execution. * **Maintenance** * Updated workflow caching and action step annotations without changing linting or fixing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
652311feb5 |
fix(studio): guard Auth Performance allocation strategy select against invalid values (#47896)
## Summary - The Connection management "Allocation strategy" select on the Auth > Performance page called its `onValueChange` handler's conversion logic with whatever value it was given, with no validation. If that handler ever fired with a value outside the `'percent' | 'connections'` enum, it would silently overwrite a correctly loaded config, converting it to the wrong absolute connection count and leaving the strategy dropdown in a blank/inconsistent state. - Extracted the percent/connections conversion into a pure, unit-tested `convertPoolSize()` helper (`PerformanceSettingsForm.utils.ts`) and added a guard so `onValueChange` ignores any value that isn't a recognized allocation unit. ## How to test 1. Under **Connection management**, switch **Allocation strategy** back and forth between "Absolute number of connections" and "Percent of max connections" — the value should convert correctly each time and the dropdown should never render blank. 2. Save, then hard-reload the page — the saved strategy and value should persist as shown. ## Test plan - [x] `PerformanceSettingsForm.utils.test.ts` — unit tests covering both conversion directions, clamping, and the invalid-value guard - [x] `PerformanceSettingsForm.test.tsx` — MSW-backed component test verifying persisted percent/absolute configs render correctly on load - [x] `pnpm test:studio` - [x] `pnpm typecheck` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Switching database pool allocation strategies now automatically converts values between percentage and connection-based units. * Values are rounded and constrained appropriately to remain within supported limits. * Allocation settings now handle invalid or zero values more safely. * **Tests** * Added coverage verifying persisted allocation strategies and pool-size conversion behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c9a649cf73 |
refactor(sql-editor): extract snippet-identity/mount/prettify/title hooks (decompose 3b/6) (#47893)
## Summary Continues the SQLEditor decomposition. Pulls four cohesive concerns out of the `SQLEditorContent` composition root into co-located `use*` hooks. ## New hooks - `useSnippetIdentity` — derives `id` / `generatedNewSnippetName` / `isLoading` from the URL + snippet store (keeps the `[urlId]` memo dep verbatim). - `useEditorMount` — the editor `onMount` (scroll restore/track) + the mount counter that lets a pre-mount diff request re-run. - `usePrettifyQuery` — formats the editor SQL in place and writes it back to the store. - `useSnippetTitleGenerator` — the title-generation mutation + `setAiTitle`. |