<!-- ccr-slack-attribution --> _Requested by **Jonny Summers-Muir** · [Slack thread](https://supabase.slack.com/archives/C0429V78ACX/p1789496187445649?thread_ts=1789496187.445649&cid=C0429V78ACX)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / CI config fix (Dependabot supply-chain policy). ## What is the current behavior? Dependabot's `npm`-ecosystem pull requests fail our Vercel preview builds. `pnpm-workspace.yaml` sets `minimumReleaseAge: 4320` (3 days), which makes `pnpm install` reject any dependency version published more recently than 3 days ago as a supply-chain safeguard. Dependabot proposes the newest available version the moment it's released, so a Dependabot PR's pinned versions can be — and repeatedly have been — younger than pnpm's 3-day cutoff at the moment CI first runs. Concrete example: branch `dependabot/npm_and_yarn/npm_and_yarn-a6265761c1` (commit `2e988c6`), the `design-system` Vercel preview build fails because `pnpm install` rejects `@antfu/install-pkg@2.1.0` and `@types/d3-selection@3.0.12` under the minimum-release-age policy. This is not a one-off — it recurs across many Dependabot npm PRs (e.g. #50399, #49060, #49013). Note: while investigating, I could not find a pre-existing `package-ecosystem: npm` entry in `.github/dependabot.yml` despite the repo's long history of grouped `npm_and_yarn` Dependabot PRs — meaning the previous npm update cadence (grouping across directories such as `/`, `/apps/studio`, `/e2e/studio`) was apparently running under a GitHub-managed default rather than an explicit, in-repo config. This PR makes that configuration explicit so it's actually possible to attach a `cooldown` to it (see caveats below). ## What is the new behavior? Added an explicit `package-ecosystem: npm` entry to `.github/dependabot.yml`, covering the monorepo's workspace directories (`/`, `/apps/*`, `/packages/*`, `/blocks/*`, `/e2e/*`, matching `pnpm-workspace.yaml`'s `packages:` globs), with: ```yaml cooldown: default-days: 4 ``` A `cooldown` tells Dependabot not to propose a version until it has been out for at least that many days — 4 days here, one day above pnpm's 3-day `minimumReleaseAge` gate to leave margin for scheduling/CI latency. This means Dependabot's proposals are now aligned with pnpm's acceptance window: by the time a PR is opened and CI runs, the version has already cleared the age check, so `pnpm install` no longer rejects it. This fixes the root scheduling mismatch (Dependabot proposes instantly, pnpm requires 3 days of age) rather than weakening the supply-chain check itself — `minimumReleaseAge` and `minimumReleaseAgeExclude` in `pnpm-workspace.yaml` are unchanged. This is a pure CI/dependency-tooling config change with no dependency version bumps, so `pnpm-lock.yaml` did not need to be regenerated. ## Validation - YAML syntax: parsed `.github/dependabot.yml` with `yaml.safe_load` — valid. - pnpm accepts the config: ran `pnpm install --lockfile-only --filter design-system...` (the project named in the failing example) from a clean checkout; it printed `Verifying lockfile against supply-chain policies (3424 entries)... Lockfile passes supply-chain policies`, confirming `pnpm-workspace.yaml`'s `minimumReleaseAge`/`minimumReleaseAgeExclude` config (untouched by this PR) still parses and behaves correctly. - Did not attempt a full monorepo `pnpm install`/lockfile regen: not needed since no dependency versions changed, and a full workspace install is separately blocked in this environment by an unrelated `npm.jsr.io` 403 on `apps/studio`'s `@jsr/std__path` dependency. - Could not validate the new `directories` (plural/glob) `dependabot.yml` field against GitHub's live Dependabot config validator from this sandbox (no network path to it); it is a documented, GA `dependabot.yml` option, but worth a maintainer double-checking the "Insights > Dependency graph > Dependabot" config validation tab once this PR is open. ## Additional context Caveat for a maintainer with org-admin visibility: since no npm entry existed in version control before this PR, it's worth confirming there isn't a separate, org/enterprise-level Dependabot configuration also managing npm updates for this repo (which could now run alongside this new repo-level entry). If one exists, this repo-level entry should take precedence per GitHub's documented behavior, but it's worth a quick check in org Settings, Code security, to rule out duplicate/conflicting scheduling. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01BGhzwT3p6k35oEBJa8ivgH Co-authored-by: Claude <noreply@anthropic.com>
Supabase
Supabase is the Postgres development platform. We're building the features of Firebase using enterprise-grade open source tools.
- Hosted Postgres Database. Docs
- Authentication and Authorization. Docs
- Auto-generated APIs.
- Functions.
- File Storage. Docs
- AI + Vector/Embeddings Toolkit. Docs
- Dashboard
Watch "releases" of this repo to get notified of major updates.
Documentation
For full documentation, visit supabase.com/docs
To see how to Contribute, visit Getting Started
Community & Support
- Community Forum. Best for: help with building, discussion about database best practices.
- GitHub Issues. Best for: bugs and errors you encounter using Supabase.
- Email Support. Best for: problems with your database or infrastructure.
- Discord. Best for: sharing your applications and hanging out with the community.
How it works
Supabase is a combination of open source tools. We’re building the features of Firebase using enterprise-grade, open source products. If the tools and communities exist, with an MIT, Apache 2, or equivalent open license, we will use and support that tool. If the tool doesn't exist, we build and open source it ourselves. Supabase is not a 1-to-1 mapping of Firebase. Our aim is to give developers a Firebase-like developer experience using open source tools.
Architecture
Supabase is a hosted platform. You can sign up and start using Supabase without installing anything. You can also self-host and develop locally.
- Postgres is an object-relational database system with over 30 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.
- Realtime is an Elixir server that allows you to listen to PostgreSQL inserts, updates, and deletes using websockets. Realtime polls Postgres' built-in replication functionality for database changes, converts changes to JSON, then broadcasts the JSON over websockets to authorized clients.
- PostgREST is a web server that turns your PostgreSQL database directly into a RESTful API.
- GoTrue is a JWT-based authentication API that simplifies user sign-ups, logins, and session management in your applications.
- Storage a RESTful API for managing files in S3, with Postgres handling permissions.
- pg_graphql a PostgreSQL extension that exposes a GraphQL API.
- postgres-meta is a RESTful API for managing your Postgres, allowing you to fetch tables, add roles, and run queries, etc.
- Envoy is a cloud-native, high-performance edge and service proxy.
Client libraries
Our approach for client libraries is modular. Each sub-library is a standalone implementation for a single external system. This is one of the ways we support existing tools.
| Language | Client | Feature-Clients (bundled in Supabase client) | ||||
|---|---|---|---|---|---|---|
| Supabase | PostgREST | GoTrue | Realtime | Storage | Functions | |
| ⚡️ Official ⚡️ | ||||||
| JavaScript (TypeScript) | supabase-js | postgrest-js | auth-js | realtime-js | storage-js | functions-js |
| Flutter | supabase-flutter | postgrest | supabase_auth | supabase_realtime | supabase_storage | supabase_functions |
| Swift | supabase-swift | postgrest-swift | auth-swift | realtime-swift | storage-swift | functions-swift |
| Python | supabase-py | postgrest-py | gotrue-py | realtime-py | storage-py | functions-py |
| 💚 Community 💚 | ||||||
| C# | supabase-csharp | postgrest-csharp | gotrue-csharp | realtime-csharp | storage-csharp | functions-csharp |
| Go | - | postgrest-go | gotrue-go | - | storage-go | functions-go |
| Java | - | - | gotrue-java | - | storage-java | - |
| Kotlin | supabase-kt | postgrest-kt | auth-kt | realtime-kt | storage-kt | functions-kt |
| Ruby | supabase-rb | postgrest-rb | - | - | - | - |
| Rust | - | postgrest-rs | - | - | - | - |
| Godot Engine (GDScript) | supabase-gdscript | - | - | - | - | - |
Badges
[](https://supabase.com)
<a href="https://supabase.com">
<img
width="168"
height="30"
src="https://supabase.com/badge-made-with-supabase.svg"
alt="Made with Supabase"
/>
</a>
[](https://supabase.com)
<a href="https://supabase.com">
<img
width="168"
height="30"
src="https://supabase.com/badge-made-with-supabase-dark.svg"
alt="Made with Supabase"
/>
</a>
Translations
- Arabic | العربية
- Albanian / Shqip
- Bangla / বাংলা
- Bulgarian / Български
- Catalan / Català
- Croatian / Hrvatski
- Czech / čeština
- Danish / Dansk
- Dutch / Nederlands
- English
- Estonian / eesti keel
- Finnish / Suomalainen
- French / Français
- German / Deutsch
- Greek / Ελληνικά
- Gujarati / ગુજરાતી
- Hebrew / עברית
- Hindi / हिंदी
- Hungarian / Magyar
- Nepali / नेपाली
- Indonesian / Bahasa Indonesia
- Italiano / Italian
- Japanese / 日本語
- Korean / 한국어
- Lithuanian / lietuvių
- Latvian / latviski
- Malay / Bahasa Malaysia
- Norwegian (Bokmål) / Norsk (Bokmål)
- Persian / فارسی
- Polish / Polski
- Portuguese / Português
- Portuguese (Brazilian) / Português Brasileiro
- Romanian / Română
- Russian / Pусский
- Serbian / Srpski
- Sinhala / සිංහල
- Slovak / slovenský
- Slovenian / Slovenščina
- Spanish / Español
- Simplified Chinese / 简体中文
- Swedish / Svenska
- Thai / ไทย
- Traditional Chinese / 繁體中文
- Turkish / Türkçe
- Ukrainian / Українська
- Vietnamese / Tiếng Việt
- List of translations



