chore: production deploy - #6148
Conversation
supabase-cli-releaser
Bot
commented
Aug 11, 2026
- fix(cli): skip redundant network create (fix(cli): skip redundant network create #6130)
- test(process-compose): deflake the cleanup timeout test (test(process-compose): deflake the cleanup timeout test #6128)
- feat(cli): skip vault sync (feat(cli): skip vault sync #6131)
- chore(ci): bump the actions-major group with 2 updates (chore(ci): bump the actions-major group with 2 updates #6133)
- fix(docker): bump postgrest/postgrest from v14.16 to v16.0 in /apps/cli-go/pkg/config/templates (fix(docker): bump postgrest/postgrest from v14.16 to v16.0 in /apps/cli-go/pkg/config/templates #6134)
- chore(cli): define error taxonomy (chore(cli): define error taxonomy #6132)
- docs(cli): document error classification (docs(cli): document error classification #6138)
- fix(cli): retry local db connection (fix(cli): retry local db connection #6137)
- chore(cli): attach failure metadata (chore(cli): attach failure metadata #6139)
- fix(cli): port shadow database provisioning to native TS (CLI-1956) (fix(cli): port shadow database provisioning to native TS (CLI-1956) #6027)
- fix(cli): port db reset --experimental remote schema-files path to native TS (CLI-1958) (fix(cli): port db reset --experimental remote schema-files path to native TS (CLI-1958) #6062)
- docs(cli): document untagged fingerprints (docs(cli): document untagged fingerprints #6141)
- test(cli): make homeDir-dependent tests hermetic (test(cli): make homeDir-dependent tests hermetic #5993)
- fix(deps): bump go.opentelemetry.io/otel from 1.44.0 to 1.45.0 in /apps/cli-go in the go-minor group across 1 directory (fix(deps): bump go.opentelemetry.io/otel from 1.44.0 to 1.45.0 in /apps/cli-go in the go-minor group across 1 directory #6144)
- fix(docker): bump the docker-minor group in /apps/cli-go/pkg/config/templates with 3 updates (fix(docker): bump the docker-minor group in /apps/cli-go/pkg/config/templates with 3 updates #6145)
- chore(ci): bump the actions-major group with 2 updates (chore(ci): bump the actions-major group with 2 updates #6146)
## TL;DR fixes `supabase start --network-id` failing with `failed to create docker network` when the network already exists but the create request dies in transit, for example an EPIPE through a docker socket forwarder. was caused by `legacyEnsureNetwork` always spawning a `docker network create` that is a guaranteed conflict for an existing network, and is now fixed by: probing `docker network inspect` first and only creating on a miss, the same shape `ensureDockerNetwork` already uses. The shared bootstrap path also covers `db start` and `db reset`.... ## ref: - closes: CLI-2151 - closes: #6127
## TL;DR `SupervisorRuntime.unit.test.ts` intermittently fails on CI with `ENOENT … cleanup-worker.pid`: <img width="731" height="520" alt="image" src="https://github.com/user-attachments/assets/08fae2db-d372-4c27-aa72-a4e56c7ac1ee" /> the cleanup command's timeout budget starts at spawn, so `100ms` had to cover node booting, spawning the worker and writing the pid file. lose that race and the tree gets killed before the write lands. raised to 2s, any value bounds the tree, so what the test asserts is unchanged.... ## ref: - seen on: https://github.com/supabase/cli/actions/runs/31211231481/job/92974279931
## TL;DR Adds `--skip-vault` to `supabase db push`, allowing migrations to run without resolving or syncing configured Vault secrets ## What’s introduced? `supabase db push --skip-vault` skips `[db.vault]` decryption and remote synchronization while preserving migrations, roles, seeds, target selection, and confirmation behavior. Existing behavior remains unchanged when the flag is omitted... ## Why was it needed? Database pushes could overwrite environment-specific remote secrets with local values. They could also fail before connecting when Vault decryption keys were intentionally unavailable. ## Ref - Closes #3815 - Closes CLI-1800
Bumps the actions-major group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.4 to 4.37.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/init's releases</a>.</em></p> <blockquote> <h2>v4.37.5</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <ul> <li>Cache CodeQL CLI version information across Actions steps. <a href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li> <li>Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. <a href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/d1ba80a13dd99fba24a470575428917156a28b43"><code>d1ba80a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4067">#4067</a> from github/update-v4.37.5-1cd4d01d5</li> <li><a href="https://github.com/github/codeql-action/commit/e74600b0d945db9734eb044f95cd43f34b773451"><code>e74600b</code></a> Update changelog for v4.37.5</li> <li><a href="https://github.com/github/codeql-action/commit/1cd4d01d58f636bbdbffbfd3c121b3446d07e9f3"><code>1cd4d01</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4061">#4061</a> from github/henrymercer/turbo-system</li> <li><a href="https://github.com/github/codeql-action/commit/d2bfc30bc3373a3ec945dc3f93bc8b8f07fa16b9"><code>d2bfc30</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4050">#4050</a> from github/mbg/status/registries</li> <li><a href="https://github.com/github/codeql-action/commit/68028fcb1605f3cdd37e4e1845c3f78af017a3ea"><code>68028fc</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4062">#4062</a> from github/sam-robson/migrate-enterprise-release-pat</li> <li><a href="https://github.com/github/codeql-action/commit/c29563eeaafbc75499c7bb0d74bf77b3506c1cbd"><code>c29563e</code></a> ci: use federated enterprise release PAT</li> <li><a href="https://github.com/github/codeql-action/commit/155e5229973b426bd1ae2f83bb1bf42417fa2a8f"><code>155e522</code></a> Link the PR from the changelog entry</li> <li><a href="https://github.com/github/codeql-action/commit/2d3b351ea6452a9b21346f8d64567e5b833924de"><code>2d3b351</code></a> Handle network errors when streaming the CodeQL bundle download</li> <li><a href="https://github.com/github/codeql-action/commit/5d3eb98e4a780bfe1a53f57fbdc278ea5da1274b"><code>5d3eb98</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4055">#4055</a> from github/dependabot/npm_and_yarn/npm-minor-203262...</li> <li><a href="https://github.com/github/codeql-action/commit/c5f739bd6460e096aaf40962517e46a846b8b6b1"><code>c5f739b</code></a> Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-2032624187</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/f205ea1c3313d32999d8d6a48b4f6530d4437b38...d1ba80a13dd99fba24a470575428917156a28b43">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/analyze` from 4.37.4 to 4.37.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's releases</a>.</em></p> <blockquote> <h2>v4.37.5</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <ul> <li>Cache CodeQL CLI version information across Actions steps. <a href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li> <li>Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. <a href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/d1ba80a13dd99fba24a470575428917156a28b43"><code>d1ba80a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4067">#4067</a> from github/update-v4.37.5-1cd4d01d5</li> <li><a href="https://github.com/github/codeql-action/commit/e74600b0d945db9734eb044f95cd43f34b773451"><code>e74600b</code></a> Update changelog for v4.37.5</li> <li><a href="https://github.com/github/codeql-action/commit/1cd4d01d58f636bbdbffbfd3c121b3446d07e9f3"><code>1cd4d01</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4061">#4061</a> from github/henrymercer/turbo-system</li> <li><a href="https://github.com/github/codeql-action/commit/d2bfc30bc3373a3ec945dc3f93bc8b8f07fa16b9"><code>d2bfc30</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4050">#4050</a> from github/mbg/status/registries</li> <li><a href="https://github.com/github/codeql-action/commit/68028fcb1605f3cdd37e4e1845c3f78af017a3ea"><code>68028fc</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4062">#4062</a> from github/sam-robson/migrate-enterprise-release-pat</li> <li><a href="https://github.com/github/codeql-action/commit/c29563eeaafbc75499c7bb0d74bf77b3506c1cbd"><code>c29563e</code></a> ci: use federated enterprise release PAT</li> <li><a href="https://github.com/github/codeql-action/commit/155e5229973b426bd1ae2f83bb1bf42417fa2a8f"><code>155e522</code></a> Link the PR from the changelog entry</li> <li><a href="https://github.com/github/codeql-action/commit/2d3b351ea6452a9b21346f8d64567e5b833924de"><code>2d3b351</code></a> Handle network errors when streaming the CodeQL bundle download</li> <li><a href="https://github.com/github/codeql-action/commit/5d3eb98e4a780bfe1a53f57fbdc278ea5da1274b"><code>5d3eb98</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4055">#4055</a> from github/dependabot/npm_and_yarn/npm-minor-203262...</li> <li><a href="https://github.com/github/codeql-action/commit/c5f739bd6460e096aaf40962517e46a846b8b6b1"><code>c5f739b</code></a> Merge branch 'main' into dependabot/npm_and_yarn/npm-minor-2032624187</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/f205ea1c3313d32999d8d6a48b4f6530d4437b38...d1ba80a13dd99fba24a470575428917156a28b43">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…li-go/pkg/config/templates (#6134) Bumps postgrest/postgrest from v14.16 to v16.0. [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## TL;DR Defines a shared, CLI error taxonomy for KPI reporting.. ## What's introduced? - A shared taxonomy for describing why a CLI command failed, whether the failure is actionable, and how the user can recover. - Consistent classifications across known CLI errors, backed by automated coverage that prevents new errors from going unclassified. - Stable error fingerprints and precise definitions for measuring recovery, repeat failures, and internal or unknown CLI bugs. ## Why is it needed? `cli_command_executed` tells us that a command failed, but not whether it was user-actionable, caused by an external service, or a CLI bug. This establishes that distinction without capturing raw error text or user-specific data & lays the foundation for CLI-1561 (completed locally, will push once this lands in) to add these fields to telemetry... ## ref - Closes CLI-1560 - supersedes/extends: #5829 --------- Co-authored-by: Julien Goux <hi@jgoux.dev>
## TL;DR fixes `supabase db start` on `Windows/WSL2` killing a healthy Postgres container right after it becomes healthy, which was caused by a single 2 second host connection attempt while Docker Desktop publishes the container port with a short delay, and is now fixed by retrying the first fresh volume connection on dial level errors with 1 second backoff for up to 10 attempts. Auth and config errors still fail on the first attempt, and the error text on exhausted retries is unchanged... ## ref: - closes: #6136 - closes CLI-2152
## TL;DR `cli_command_executed` already records that a command failed, but not why, so failures cannot be separated into user mistakes, external service problems, and CLI bugs. Failed events now carry sanitized classification metadata derived from the error the command raised, never from its message text... ## What's introduced? - Failed events carry `error_kind`, `error_category`, `error_fingerprint`, `has_suggestion`, `suggestion_type`, and `suggested_command` when the remediation is one of a small allowlist of commands. Successful events are unchanged. - Every value comes from a closed vocabulary, so no raw error text reaches PostHog, and paths, SQL, project refs, hostnames, tokens, and other user specific values cannot be captured. - `workflow` is reserved in the event catalog and left unset until there is an agreed closed vocabulary for it. ## Why is it needed? Recovery rate, repeat failures, and the internal or unknown bug rate are all computed from these fields, so until they exist those reports have nothing to filter or group on. Classifying each failure where the error is raised makes that measurable without sending the error text itself.... ## Ref - closes: CLI-1561
…6027) ## What changed Ports the shadow-database provisioning used by `db diff`/`db pull` (create → health-wait → connect → setup/migrate → remove) from the hidden Go `db __shadow` seam to native TypeScript, and removes that seam from `apps/cli-go/cmd/db.go`. This was the last local-container orchestration `db diff`/`db pull`'s native engines still delegated to Go for. New shared primitives live in `legacy/shared/db-bootstrap/shadow-database.ts` (create/connect/setup/migrate/remove — kept as separate composable pieces rather than one monolithic function, since the two known future callers need different subsets: `migration squash` (CLI-1969) needs create → health-wait → connect → setup only, while `db diff --use-pgadmin` (CLI-1968) needs create → health-wait → migrate). `legacy/commands/db/shared/legacy-shadow-source.ts` composes these for `db diff`/`db pull`'s `--target-local` declarative branch, which also needs pg-delta. `legacy-pgdelta.apply.ts` is a from-scratch port of Go's `pgdelta.ApplyDeclarative`. Hoisted a shared `legacyResolveDbSetupPrelude` (`db-setup.ts`) so fresh-db setup and shadow setup stop duplicating the same JWKS/image-pull resolution, per this repo's "Hoist Before You Duplicate" rule. ## Why Part of the M9 milestone (Go removal) — this and the three PRs below it in the stack (#6021 CLI-1953, #6022 CLI-1954, #6026 CLI-1955) progressively remove the Go delegations that anchor the bundled Go binary. This PR removes the last one blocking `db diff`/`db pull`'s native engines. ## Reviewer-relevant context - The parent stack PRs (#6021, #6022, #6026) have all merged, so this diff is now standalone. - An earlier revision described a "randomized per-invocation staged secret dir" for the shadow container; review showed that machinery was dead — secrets are delivered straight into the container via `docker cp` and nothing ever creates a staged dir on disk — so it was deleted outright. `legacyRemoveShadowDatabase` is now just `(spawner, containerId)`. - Neither `db diff` nor `db pull` wires the `LegacyDeclarativeSeam` layer any more — `db diff --use-pgadmin`/`--use-pg-schema` proxy the whole invocation to the bundled Go binary rather than going through the seam. The seam now serves only `db schema declarative generate`/`sync`'s baseline/declarative catalog modes (the remaining CLI-1959 scope). - A deep-review fix batch is included on top of the port (observable `db diff`/`db pull` behavior is unchanged except where noted): shared project-id resolution at every pg-delta site (fixes `supabase_edge_runtime_:` volume binds under env-only project ids), Go's `PGDELTA_DEBUG` shadow-catalog export in `db diff`, config validation before the "Creating shadow database..." banner, the relative path in the declarative-dir-not-found error, Go `int64` bounds in the apply-output decoder, byte-ordered (Go `fs.WalkDir`) SQL-file walking, remote-override gating for ~20 more config keys, `DEBUG` resolution through the merged project env like viper, Go's exact unhealthy-container line format, `%q`/`TrimSpace`-exact apply-failure rendering, percent-round-tripping of special-character shadow DB passwords, and a rename of the apply-side error class that shared its `Data.TaggedError` tag with `declarative.errors.ts`'s. - New shadow/apply error classes declare the error-actionability taxonomy metadata that landed on develop meanwhile (#6132), and `db diff`/`db pull`'s SIDE_EFFECTS.md now document the in-process shadow bring-up (dotenv/TLS/roles.sql reads and the `SUPABASE_*` override family). - The shadow container honors a config.toml `[db] password` — a deliberate TS extension carried over from develop's `--local` handling (Go rejects that key at config load and always uses `postgres`); documented at the builder, with the strict-rejection question tracked as a follow-up. Fixes CLI-1956 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tive TS (CLI-1958) (#6062) ## What changed Ports `db reset`'s `--experimental` remote schema-files path from a Go-binary delegation to native TypeScript, removing the last `LegacyGoProxy` dependency from `db reset`'s remote branch. Trigger (matches Go's `apply.MigrateAndSeed` three-conjunct gate exactly): `--experimental`/`SUPABASE_EXPERIMENTAL` set, no explicit `--version`/`--last`, and `[experimental.pgdelta].enabled` unset. Body: globs `[db.migrations].schema_paths` and execs each matched file with no history tracking (no version row, no `RESET ALL` between files) — reproducing two undocumented Go quirks byte-for-byte: - Default `schema_paths = []` makes this a **silent no-op** (schemas/seeds still drop and reseed, nothing gets applied). - A **partial** glob failure (some patterns match, some don't) is silently swallowed; only a **total** failure (nothing matches at all) aborts the reset. New shared primitives: `legacyApplySchemaFiles` (`legacy-migration-apply.ts`) and a hoisted `legacy-sql-files-glob.ts` (replacing three separate hand-rolled copies of Go's `Glob.SQLFiles` traversal that had existed across `db push`'s seed path, this new schema-files path, and `start`/`migration down`'s seed path — the third one had already silently diverged, missing directory-entry expansion; that's fixed too). This path connects directly (no shadow database involved) — confirmed via go-parity-auditor, addressing the issue's own note about overlapping with CLI-1956's shadow-provisioning work (a separate, still-in-progress issue in another PR): there turned out to be no actual dependency. ## Known, deliberately-deferred gap (tracked separately) `legacyMigrateAndSeed` (shared by `migration down` and native `supabase start`'s fresh-volume setup) does not yet implement this same schema-files branch, so `supabase start --experimental` on a fresh volume doesn't reproduce Go's behavior. This is **pre-existing** (not introduced here) and out of scope for `db reset` — filed as [CLI-2040](https://linear.app/supabase/issue/CLI-2040) with the same go-parity-auditor findings, and the relevant docstring here now points at it instead of asserting (falsely) that the gap doesn't exist. ## Review notes Reviewed independently by go-parity-auditor, engineer-reviewer, and architect-reviewer — all three converged on the same two follow-ups (now fixed): a stale "unreachable" docstring papering over the CLI-2040 gap, and an incomplete hoist that left a third, silently-diverging copy of the shared glob logic in `db push`/`start`/`migration down`'s seed path. Consolidating that hoist also surfaced and fixed a real latent bug in the shared glob's Windows-path handling (`toSlash` was applying backslash-to-slash conversion unconditionally instead of Windows-only, which would have corrupted backslash-escaped glob patterns on non-Windows once rerouted). Added test coverage for schema-file application order, directory-entry expansion, and the new `SUPABASE_DB_MIGRATIONS_SCHEMA_PATHS` env-override branches. Fixes CLI-1958
- extends: #6139 & CLI-1561
Tests that combined `mockRuntimeInfo`'s fixed default `homeDir` (`/tmp/supabase-cli-test-home`) with a real `FileSystem` layer silently picked up stale files left by older test runs or manual CLI invocations — e.g. a leftover `~/.supabase/profile` containing `supabase-staging` broke two `legacy-cli-config` unit tests on a developer machine. - `mockRuntimeInfo` / `mockTelemetryRuntime` now default to a per-process unique path that is never created on disk, so the stale-state class of failure can't recur. - Tests that build the real `legacyCliConfigLayer` / `legacyCredentialsLayer` against a real filesystem (the six `*.layers.unit.test.ts` layer-exposure tests, the four experimental-gate tests, and `legacy-cli-config.layer.unit.test.ts`) now pin `homeDir` to a per-test temp dir and isolate ambient env via a new `legacyIsolatedHomeLayer` helper, which also replaces the hand-rolled `TelemetryRuntime` blocks with `mockTelemetryRuntime`. - The hermeticity rule is documented in the testing policy in `apps/cli/AGENTS.md`. Verified by recreating a poisoned `/tmp/supabase-cli-test-home` (stale profile + access token) and running the full core suite against it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…ps/cli-go in the go-minor group across 1 directory (#6144) Bumps the go-minor group with 1 update in the /apps/cli-go directory: [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go). Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/open-telemetry/opentelemetry-go/releases">go.opentelemetry.io/otel's releases</a>.</em></p> <blockquote> <h2>Release v1.45.0/v0.67.0/v0.21.0/v0.0.18</h2> <h2>Overview</h2> <h3>Added</h3> <ul> <li>Add experimental observability metrics to <code>BatchProcessor</code> in <code>go.opentelemetry.io/otel/sdk/log</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124">#7124</a>)</li> <li>Add the experimental <code>WithUnsafeAttributes</code> no-copy attribute option to <code>go.opentelemetry.io/otel/metric/x</code> for future performance improvements. This API is a work in progress. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251">#8251</a>)</li> <li>Add <code>Map</code> and <code>MapValue</code> functions for the new <code>MAP</code> attribute type in <code>go.opentelemetry.io/otel/attribute</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445">#8445</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlplog</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/zipkin</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Apply <code>AttributeValueLengthLimit</code> recursively to values contained in <code>attribute.MAP</code> attributes in <code>go.opentelemetry.io/otel/sdk/trace</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454">#8454</a>)</li> <li>Remove duplicate keys from <code>attribute.MAP</code> values in <code>go.opentelemetry.io/otel/sdk/resource</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/log</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in span, event, link, and instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/trace</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in measurement and instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/metric</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Extend <code>WithAllowKeyDuplication</code> in <code>go.opentelemetry.io/otel/sdk/log</code> to disable duplicate-key removal in <code>attribute.MAP</code> values for instrumentation scope attributes. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Add the <code>go.opentelemetry.io/otel/semconv/v1.42.0</code> package. The package contains semantic conventions from the <code>v1.42.0</code> version of the OpenTelemetry Semantic Conventions. See the <a href="https://github.com/open-telemetry/opentelemetry-go/blob/HEAD/semconv/v1.42.0/MIGRATION.md">migration documentation</a> for information on how to upgrade from <code>go.opentelemetry.io/otel/semconv/v1.41.0</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484">#8484</a>)</li> <li>Add <code>WithoutPanicRecording</code> as a <code>TracerProviderOption</code> in <code>go.opentelemetry.io/otel/sdk/trace</code> to disable exception event recording for panics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532">#8532</a>)</li> <li>Add the <code>go.opentelemetry.io/otel/semconv/v1.43.0</code> package. The package contains semantic conventions from the <code>v1.43.0</code> version of the OpenTelemetry Semantic Conventions. See the <a href="https://github.com/open-telemetry/opentelemetry-go/blob/HEAD/semconv/v1.43.0/MIGRATION.md">migration documentation</a> for information on how to upgrade from <code>go.opentelemetry.io/otel/semconv/v1.42.0</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628">#8628</a>)</li> </ul> <h3>Changed</h3> <ul> <li><code>HistogramReservoir</code> in <code>go.opentelemetry.io/otel/sdk/metric/exemplar</code> now uses a time-unbiased sampling algorithm for exemplars. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306">#8306</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> Use <code>go.opentelemetry.io/otel/attribute.Value</code> and <code>go.opentelemetry.io/otel/attribute.KeyValue</code> for log bodies and attributes in <code>go.opentelemetry.io/otel/log</code>, <code>go.opentelemetry.io/otel/log/logtest</code>, <code>go.opentelemetry.io/otel/sdk/log</code>, and <code>go.opentelemetry.io/otel/sdk/log/logtest</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>Encode log bodies and attributes as <code>go.opentelemetry.io/otel/attribute.Value</code> JSON in <code>go.opentelemetry.io/otel/exporters/stdout/stdoutlog</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>Improve the performance of hashing <code>BOOLSLICE</code>, <code>INT64SLICE</code>, <code>FLOAT64SLICE</code>, and <code>STRINGSLICE</code> attribute values by avoiding reflection for short slices in <code>go.opentelemetry.io/otel/attribute</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511">#8511</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> <code>WithEndpointURL</code> in <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp</code> no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code> and with setting the endpoint through <code>OTEL_EXPORTER_OTLP_METRICS_ENDPOINT</code>. If the URL has no path component, the root path (<code>/</code>) is used. Use <code>WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))</code> to preserve the previous behavior. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538">#8538</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> <code>WithEndpointURL</code> in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp</code> no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code> and with setting the endpoint through <code>OTEL_EXPORTER_OTLP_TRACES_ENDPOINT</code>. If the URL has no path component, the root path (<code>/</code>) is used. Use <code>WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))</code> to preserve the previous behavior. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538">#8538</a>)</li> </ul> <h3>Deprecated</h3> <ul> <li>Deprecate <code>WithExportBufferSize</code> in <code>go.opentelemetry.io/otel/sdk/log</code>. The option remains available for source compatibility but no longer affects behavior; <code>BatchProcessor</code> no longer maintains a separate export-request buffer. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620">#8620</a>)</li> </ul> <h3>Removed</h3> <ul> <li>⚠️ <strong>Breaking Change:</strong> Remove <code>Kind</code>, <code>Value</code>, <code>KeyValue</code>, their constructors, and attribute conversion helpers from <code>go.opentelemetry.io/otel/log</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> Remove the <code>AttributeValueLengthLimit</code> and <code>AttributeCountLimit</code> fields from <code>RecordFactory</code> in <code>go.opentelemetry.io/otel/sdk/log/logtest</code>; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556">#8556</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Apply TLS certificates configured through environment variables to gRPC connections in <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc</code>.</li> <li>Prevent panics in <code>go.opentelemetry.io/otel/bridge/opentracing</code> when OpenTracing baggage is propagated concurrently with <code>Span.SetBaggageItem</code>.</li> <li>Fix an off-by-one error in <code>FixedSizeReservoir</code> in <code>go.opentelemetry.io/otel/sdk/metric/exemplar</code> that prevented the first exemplar from being sampled after the reservoir was filled. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309">#8309</a>)</li> <li>Interpret HTTP <code>Retry-After</code> header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp</code>, <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp</code>, and <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383">#8383</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md">go.opentelemetry.io/otel's changelog</a>.</em></p> <blockquote> <h2>[1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03</h2> <h3>Added</h3> <ul> <li>Add experimental observability metrics to <code>BatchProcessor</code> in <code>go.opentelemetry.io/otel/sdk/log</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124">#7124</a>)</li> <li>Add the experimental <code>WithUnsafeAttributes</code> no-copy attribute option to <code>go.opentelemetry.io/otel/metric/x</code> for future performance improvements. This API is a work in progress. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251">#8251</a>)</li> <li>Add <code>Map</code> and <code>MapValue</code> functions for the new <code>MAP</code> attribute type in <code>go.opentelemetry.io/otel/attribute</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445">#8445</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlplog</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Support <code>MAP</code> attributes in <code>go.opentelemetry.io/otel/exporters/zipkin</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453">#8453</a>)</li> <li>Apply <code>AttributeValueLengthLimit</code> recursively to values contained in <code>attribute.MAP</code> attributes in <code>go.opentelemetry.io/otel/sdk/trace</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454">#8454</a>)</li> <li>Remove duplicate keys from <code>attribute.MAP</code> values in <code>go.opentelemetry.io/otel/sdk/resource</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/log</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in span, event, link, and instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/trace</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Remove duplicate keys by default from <code>attribute.MAP</code> values in measurement and instrumentation scope attributes in <code>go.opentelemetry.io/otel/sdk/metric</code> using last-value-wins semantics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Extend <code>WithAllowKeyDuplication</code> in <code>go.opentelemetry.io/otel/sdk/log</code> to disable duplicate-key removal in <code>attribute.MAP</code> values for instrumentation scope attributes. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471">#8471</a>)</li> <li>Add the <code>go.opentelemetry.io/otel/semconv/v1.42.0</code> package. The package contains semantic conventions from the <code>v1.42.0</code> version of the OpenTelemetry Semantic Conventions. See the <a href="https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md">migration documentation</a> for information on how to upgrade from <code>go.opentelemetry.io/otel/semconv/v1.41.0</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484">#8484</a>)</li> <li>Add <code>WithoutPanicRecording</code> as a <code>TracerProviderOption</code> in <code>go.opentelemetry.io/otel/sdk/trace</code> to disable exception event recording for panics. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532">#8532</a>)</li> <li>Add the <code>go.opentelemetry.io/otel/semconv/v1.43.0</code> package. The package contains semantic conventions from the <code>v1.43.0</code> version of the OpenTelemetry Semantic Conventions. See the <a href="https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md">migration documentation</a> for information on how to upgrade from <code>go.opentelemetry.io/otel/semconv/v1.42.0</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628">#8628</a>)</li> </ul> <h3>Changed</h3> <ul> <li><code>HistogramReservoir</code> in <code>go.opentelemetry.io/otel/sdk/metric/exemplar</code> now uses a time-unbiased sampling algorithm for exemplars. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306">#8306</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> Use <code>go.opentelemetry.io/otel/attribute.Value</code> and <code>go.opentelemetry.io/otel/attribute.KeyValue</code> for log bodies and attributes in <code>go.opentelemetry.io/otel/log</code>, <code>go.opentelemetry.io/otel/log/logtest</code>, <code>go.opentelemetry.io/otel/sdk/log</code>, and <code>go.opentelemetry.io/otel/sdk/log/logtest</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>Encode log bodies and attributes as <code>go.opentelemetry.io/otel/attribute.Value</code> JSON in <code>go.opentelemetry.io/otel/exporters/stdout/stdoutlog</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>Improve the performance of hashing <code>BOOLSLICE</code>, <code>INT64SLICE</code>, <code>FLOAT64SLICE</code>, and <code>STRINGSLICE</code> attribute values by avoiding reflection for short slices in <code>go.opentelemetry.io/otel/attribute</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511">#8511</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> <code>WithEndpointURL</code> in <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp</code> no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code> and with setting the endpoint through <code>OTEL_EXPORTER_OTLP_METRICS_ENDPOINT</code>. If the URL has no path component, the root path (<code>/</code>) is used. Use <code>WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))</code> to preserve the previous behavior. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538">#8538</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> <code>WithEndpointURL</code> in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp</code> no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code> and with setting the endpoint through <code>OTEL_EXPORTER_OTLP_TRACES_ENDPOINT</code>. If the URL has no path component, the root path (<code>/</code>) is used. Use <code>WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))</code> to preserve the previous behavior. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538">#8538</a>)</li> </ul> <h3>Deprecated</h3> <ul> <li>Deprecate <code>WithExportBufferSize</code> in <code>go.opentelemetry.io/otel/sdk/log</code>. The option remains available for source compatibility but no longer affects behavior; <code>BatchProcessor</code> no longer maintains a separate export-request buffer. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620">#8620</a>)</li> </ul> <h3>Removed</h3> <ul> <li>⚠️ <strong>Breaking Change:</strong> Remove <code>Kind</code>, <code>Value</code>, <code>KeyValue</code>, their constructors, and attribute conversion helpers from <code>go.opentelemetry.io/otel/log</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490">#8490</a>)</li> <li>⚠️ <strong>Breaking Change:</strong> Remove the <code>AttributeValueLengthLimit</code> and <code>AttributeCountLimit</code> fields from <code>RecordFactory</code> in <code>go.opentelemetry.io/otel/sdk/log/logtest</code>; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556">#8556</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Apply TLS certificates configured through environment variables to gRPC connections in <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc</code>.</li> <li>Prevent panics in <code>go.opentelemetry.io/otel/bridge/opentracing</code> when OpenTracing baggage is propagated concurrently with <code>Span.SetBaggageItem</code>.</li> <li>Fix an off-by-one error in <code>FixedSizeReservoir</code> in <code>go.opentelemetry.io/otel/sdk/metric/exemplar</code> that prevented the first exemplar from being sampled after the reservoir was filled. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309">#8309</a>)</li> <li>Interpret HTTP <code>Retry-After</code> header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in <code>go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp</code>, <code>go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp</code>, and <code>go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp</code>. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383">#8383</a>)</li> <li>Fix a memory leak in the <code>Reservoir</code> implementation in <code>go.opentelemetry.io/otel/sdk/metric/exemplar</code>, where storing the full <code>context.Context</code> pinned large objects such as gRPC transport buffers. (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8389">#8389</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8"><code>93a693e</code></a> Release v1.45.0 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8693">#8693</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"><code>c65d435</code></a> Merge commit from fork</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/223f9fdce4e4a85d6ee2155c6a140f236db72c8b"><code>223f9fd</code></a> sdk/metric: remove obsolete randomFloat64 TODO (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8685">#8685</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/06272bc491566efb2c581c8a52e4986cfcccec5b"><code>06272bc</code></a> fix(deps): update googleapis to 6ac0973 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8694">#8694</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/a4f238f57646197d124edcf67baf4cd6ea6d0a9f"><code>a4f238f</code></a> chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#...</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/37140e78821d3cb29a33d4b601ca4645b80ceebd"><code>37140e7</code></a> chore(deps): update codspeedhq/action action to v5.0.2 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8690">#8690</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/cef0855960bce4385c7d58c40e846573c190d826"><code>cef0855</code></a> chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8689">#8689</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/e814a7281f2d52a6440c3269e139145e62801a16"><code>e814a72</code></a> Merge commit from fork</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/bfd8eb7f85d3364fdde9ad1a408df98be30acadb"><code>bfd8eb7</code></a> chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8687">#8687</a>)</li> <li><a href="https://github.com/open-telemetry/opentelemetry-go/commit/48db2c659c3b138f971273cd91ea0bcb647768e1"><code>48db2c6</code></a> chore(deps): update github/codeql-action action to v4.37.5 (<a href="https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8692">#8692</a>)</li> <li>Additional commits viewable in <a href="https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…emplates with 3 updates (#6145) Bumps the docker-minor group in /apps/cli-go/pkg/config/templates with 3 updates: supabase/studio, supabase/realtime and supabase/storage-api. Updates `supabase/studio` from 2026.08.03-sha-022b374 to 2026.08.10-sha-5b68af1 Updates `supabase/realtime` from v2.124.2 to v2.124.3 Updates `supabase/storage-api` from v1.68.10 to v1.68.15 Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the actions-major group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.5 to 4.37.6 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/init's releases</a>.</em></p> <blockquote> <h2>v4.37.6</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <ul> <li>Cache CodeQL CLI version information across Actions steps. <a href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li> <li>Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. <a href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/5595ccaf912efad79be6eef63a5619ff05969be3"><code>5595cca</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4071">#4071</a> from github/update-v4.37.6-6a9359a1b</li> <li><a href="https://github.com/github/codeql-action/commit/ec9c75796a7f2cee5af0c5ffa0b81dc3bb58754b"><code>ec9c757</code></a> Add change note for PR 4070</li> <li><a href="https://github.com/github/codeql-action/commit/45c8742e17cbd668814137f95e605d925b8722a2"><code>45c8742</code></a> Update changelog for v4.37.6</li> <li><a href="https://github.com/github/codeql-action/commit/6a9359a1bd054c53cae7bb737bd8d796cfbf3014"><code>6a9359a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4070">#4070</a> from github/mbg/remote-address/change-file-default</li> <li><a href="https://github.com/github/codeql-action/commit/065cdc0394d424981db720df63ebc570e41b775f"><code>065cdc0</code></a> Change <code>DEFAULT_CONFIG_FILE_NAME</code></li> <li><a href="https://github.com/github/codeql-action/commit/f99dd5aeee9cf92e92d0c700cb0aa7afd7bbf431"><code>f99dd5a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4066">#4066</a> from github/dependabot/npm_and_yarn/js-yaml-5.2.2</li> <li><a href="https://github.com/github/codeql-action/commit/1804b211a343d69a6584d26fb3a68a8fe6ca39d4"><code>1804b21</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4068">#4068</a> from github/mergeback/v4.37.5-to-main-d1ba80a1</li> <li><a href="https://github.com/github/codeql-action/commit/3020a2f46286abb1704269b22ada83bd0e81c64f"><code>3020a2f</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/93c3a5a40b7affbf8ea6a480767ed0db8e8d3c5c"><code>93c3a5a</code></a> Update changelog and version after v4.37.5</li> <li><a href="https://github.com/github/codeql-action/commit/266c7bdbd2ad8151d42fd682e28c126c5da068da"><code>266c7bd</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/d1ba80a13dd99fba24a470575428917156a28b43...5595ccaf912efad79be6eef63a5619ff05969be3">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/analyze` from 4.37.5 to 4.37.6 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's releases</a>.</em></p> <blockquote> <h2>v4.37.6</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.37.2 - 21 Jul 2026</h2> <ul> <li>The new address format for the <code>config-file</code> input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the <code>remote=</code> prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. <a href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li> <li>The CodeQL Action can now make use of <a href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured private registries</a> in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. <a href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li> </ul> <h2>4.37.1 - 16 Jul 2026</h2> <ul> <li><em>Upcoming breaking change</em>: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. <a href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li> </ul> <h2>4.37.0 - 08 Jul 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li> <li>In addition to the existing input format, the <code>config-file</code> input for the <code>codeql-action/init</code> step will soon support a new <code>[owner/]repo[@ref][:path]</code> format. All components except the repository name are optional. If omitted, <code>owner</code> defaults to the same owner as the repository the analysis is running for, <code>ref</code> to <code>main</code>, and <code>path</code> to <code>.github/codeql-action.yaml</code>. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li> </ul> <h2>4.36.3 - 01 Jul 2026</h2> <p>No user facing changes.</p> <h2>4.36.2 - 04 Jun 2026</h2> <ul> <li>Cache CodeQL CLI version information across Actions steps. <a href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li> <li>Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. <a href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>. <a href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/5595ccaf912efad79be6eef63a5619ff05969be3"><code>5595cca</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4071">#4071</a> from github/update-v4.37.6-6a9359a1b</li> <li><a href="https://github.com/github/codeql-action/commit/ec9c75796a7f2cee5af0c5ffa0b81dc3bb58754b"><code>ec9c757</code></a> Add change note for PR 4070</li> <li><a href="https://github.com/github/codeql-action/commit/45c8742e17cbd668814137f95e605d925b8722a2"><code>45c8742</code></a> Update changelog for v4.37.6</li> <li><a href="https://github.com/github/codeql-action/commit/6a9359a1bd054c53cae7bb737bd8d796cfbf3014"><code>6a9359a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4070">#4070</a> from github/mbg/remote-address/change-file-default</li> <li><a href="https://github.com/github/codeql-action/commit/065cdc0394d424981db720df63ebc570e41b775f"><code>065cdc0</code></a> Change <code>DEFAULT_CONFIG_FILE_NAME</code></li> <li><a href="https://github.com/github/codeql-action/commit/f99dd5aeee9cf92e92d0c700cb0aa7afd7bbf431"><code>f99dd5a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4066">#4066</a> from github/dependabot/npm_and_yarn/js-yaml-5.2.2</li> <li><a href="https://github.com/github/codeql-action/commit/1804b211a343d69a6584d26fb3a68a8fe6ca39d4"><code>1804b21</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4068">#4068</a> from github/mergeback/v4.37.5-to-main-d1ba80a1</li> <li><a href="https://github.com/github/codeql-action/commit/3020a2f46286abb1704269b22ada83bd0e81c64f"><code>3020a2f</code></a> Rebuild</li> <li><a href="https://github.com/github/codeql-action/commit/93c3a5a40b7affbf8ea6a480767ed0db8e8d3c5c"><code>93c3a5a</code></a> Update changelog and version after v4.37.5</li> <li><a href="https://github.com/github/codeql-action/commit/266c7bdbd2ad8151d42fd682e28c126c5da068da"><code>266c7bd</code></a> Rebuild</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/d1ba80a13dd99fba24a470575428917156a28b43...5595ccaf912efad79be6eef63a5619ff05969be3">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e16817571d
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
## Summary Establishes the approved managed local-stack behavior as a shared typed acceptance contract before the managed engine and CLI commands are implemented. ## Why Managed stacks span package, CLI, Git, runtime, and persistence boundaries. Encoding the decisions once gives the later implementation work a single observable contract and prevents each layer from inventing its own identity, lifecycle, port, runtime, or recovery behavior. ## What changed - Added 89 typed scenarios exported from `@supabase/stack/testing`. - Covered project, checkout, worktree, branch, and named-stack identity; exact and automatic ports; legacy read-compatible bootstrap; credentials; runtime selection; reclamation; and package/CLI ownership boundaries. - Derived the native-runtime qualification matrix from the package service catalog. - Added intentionally narrow fixture lint for catalog shape, references, write/effect pairing, diagnostics, and output projections. Product semantics remain in the scenarios and will be enforced by the real managed engine. - Exercised the existing public `createStack()` boundary to prove omitted roots stay disposable and direct package usage does not inspect Git or mutate system-wide managed state. - Added an ADR defining the contract authority, package boundaries, testing strategy, and downstream implementation handoff. ## Ownership boundary - Direct `createStack()` remains a caller-controlled, isolated stack API. - The future managed package surface owns system-aware identity, selection, ports, runtime persistence, bootstrap, and reclamation behind an injectable repository. - The CLI consumes managed results and projects them for humans and JSON; it does not implement a parallel policy path. - Persistence technology remains an adapter choice and is not part of the product contract. ## Intentional non-goals This PR does not implement the managed engine, persistent adapter, experimental commands, migration tooling, or automatic relocation after port collisions. Downstream work will execute these fixtures through the real package, repository, and CLI boundaries. ## Reviewer focus The important review surface is the scenario catalog: inputs, selected identities, permitted writes and runtime effects, diagnostics, recovery guidance, and observable outputs. The fixture lint is deliberately not a second implementation of those decisions.
## What changed \`@supabase/api\` previously modeled only the Management API v1 namespace. The upstream API publishes two OpenAPI documents (\`/api/v1-json\` and \`/api/v2-json\`), and the config endpoint needed by CLI-2156/CLI-2064 lives on v2. This PR makes v2 a first-class namespace: - **\`scripts/download-openapi.ts\`** fetches both documents from the same base URL, merges them (paths + \`components.schemas\` unioned with collision asserts; \`info.title\` normalized), applies overrides to the merged document, and validates operationId uniqueness and version/path agreement. A missing v2 document is a hard failure — tolerating it would silently delete the namespace and the hourly sync would auto-merge the deletion. - **\`scripts/generate.ts\`** derives the client namespace from the path's leading segment (\`/v2/...\` → \`api.v2.*\`) instead of the operationId prefix, with a hard error on duplicate \`(version, method)\` pairs. Adding a v3 later requires no generator changes. All 170 existing v1 operations produce byte-identical output — the regenerated \`contracts.ts\`/\`effect-client.ts\` diff is additions-only (verified: zero removed lines). - **\`scripts/openapi-overrides.json\`** gains a tolerant \`remove\` op (remove-if-present, a documented RFC 6902 deviation) and 13 entries removing the v2 webhook paths + \`APIErrorObject\`. Upstream spec bug (still present in prod): all 10 project-webhook operations share one operationId (\`allV2ProjectsByRefWebhooks\`), the 10 org-webhook ones share another — duplicated and not version-prefixed, which breaks codegen. - **\`scripts/openapi-source.json\`** (new, committed) pins the spec source base URL — \`https://api.supabase.com\` — so \`pnpm generate\` reproduces the snapshot with no env var and provenance is visible in diffs. \`SUPABASE_API_URL\` still overrides it (e.g. for staging). - **Drift detection**: \`src/generated-contract-sync.unit.test.ts\` asserts a full bijection between the committed snapshot and the generated modules in ordinary PR CI (this is what catches a hand-edited snapshot or client — the failure mode from the #6111 POC). \`pnpm generate:check\` mirrors the hourly sync's regenerate→format→diff sequence for live verification. - **\`api-package-sync.yml\`** is pinned to \`https://api.supabase.com\` so develop's hourly sync always regenerates from prod regardless of the sidecar. The proving case, \`GET /v2/projects/{ref}/config\` → \`api.v2.getProjectConfig\` (typed \`V2ProjectConfigResponse\`), was staging-only when this branch started; it shipped to production on 2026-08-11 with a byte-identical definition, the snapshot regenerates from prod exactly, and the source pin now points at prod. No merge gate remains. ## Known limitation Three v2 operations (\`v2-list-organization-members\`, \`v2-list-organization-projects\`, \`v2-list-organization-github-connections\`) declare \`style: deepObject\` object query params, which the client currently serializes as JSON strings rather than \`page[size]=...\`. Documented in the README; the typed surface is correct, the wire format for those params is not. Part of CLI-2157 (unblocks CLI-2156 and CLI-2064).
) ## What Ports `supabase functions download`'s **default Docker-unbundle path** (`--use-docker`, default `true`) from wholesale Go-binary delegation to native TypeScript, in both the `legacy` and `next` shells. `--use-api` was already native before this PR; this closes the remaining default-path gap. `--legacy-bundle` (hidden, deprecated pre-1.120.0 fallback) is **deliberately left delegating** to the Go binary — see "Scope decision" below. Ground truth: `apps/cli-go/internal/functions/download/download.go` (`downloadWithDockerUnbundle`, `downloadOne`, `extractOne`, `getErrorLogger`). Verified against it via independent go-parity-auditor passes; see inline comments in `download.ts` for file:line citations. Linear: https://linear.app/supabase/issue/CLI-1963/port-functions-download-to-native-typescript-both-shells ## Scope decision: `--legacy-bundle` stays delegated This hidden flag requires installing/upgrading a real Deno binary on the host (`InstallOrUpgradeDeno`: downloads a release zip from `denoland/deno` or a third-party ARM64 fork, extracts, chmods, installs to `~/.supabase/deno`) and shelling out to an embedded Deno script that itself pulls `deno.land` modules at runtime. This is unique in the Go CLI — no other command, and no already-ported TS command, manages a downloaded third-party binary on the host. Porting it would give the TS CLI a first-of-its-kind capability (unverified binary download + host install + runtime network fetches) purely to support functions deployed by a 3+-year-old CLI release. Full rationale, including the go-parity-auditor's findings on this seam, is recorded as a comment on the Linear issue. `docs/go-cli-porting-status.md` reflects the partial (not fully-native) status accordingly. ## Bugs found and fixed along the way - **CLI-1891-class validation gap**: slugs sourced from the Management API's function list (the "download all" path) weren't validated before download — the new Docker path's temp-file write would have reopened a path-traversal vector Go's own `downloadAll` already guards against. Fixed with the same per-slug validation Go uses, before any per-slug network/filesystem work. - **`next` shell's `--use-docker` flag was missing `Flag.withDefault(true)`** — a real default-value divergence from `legacy` (which already had it) and from Go. Note: this changes `next`'s bare `functions download` invocation to attempt Docker unbundling by default (degrading gracefully to the server-side path with a warning if Docker isn't running), matching Go and the `legacy` shell — flagging explicitly since it's the one behavior change to `next` in this diff. - **Brotli double-decompression bug**: this CLI's HTTP transport (`FetchHttpClient`, backed by the platform `fetch`) already transparently auto-decodes `Content-Encoding: br` responses while still reporting the header — confirmed empirically with a local brotli-serving test server. Go's manual `brotli.NewReader` step doesn't need porting; doing so anyway would throw on already-decoded bytes. Removed the manual decode entirely. - **Temp eszip cleanup wasn't `defer`-equivalent**: it only ran after a successful Docker run, so a network/volume/spawn failure left `supabase/.temp/output_<slug>.eszip` on disk forever. Wrapped in `Effect.ensuring` so it runs on every path, matching Go's `defer fsys.Remove(eszipPath)`. - **`.suggestion`'s leading newline was trimmed** by the generic CLI error normalizer, losing Go's blank separator line before the `--legacy-bundle` hint (`Fprintln(os.Stderr, CmdSuggestion)`). Now read raw instead of trimmed. - **"invalid eszip v2" suggestion matched as a substring**, not Go's exact per-line match (`strings.EqualFold(line, "invalid eszip v2")`) — a container log line like "error: invalid eszip v2 header" would have wrongly triggered the deno-v2 upgrade suggestion. Fixed to match Go exactly. - **`suggestLegacyBundle` was only attached on a non-zero container exit** — Go attaches it to *any* `extractOne` failure (network/volume creation, container create/start, log streaming). Widened to cover the same scope. - **Legacy Docker-download path could resolve the wrong project config**: `loadProjectConfig` without `search: false`/`tomlOnly: true` let an ancestor project's `config.toml` (or a stray `config.json`) win — Go's `flags.LoadConfig` only ever reads `supabase/config.toml` from the exact resolved workdir. Now gated on the legacy shell; `next` keeps package defaults. - **`--network-id container:<name|id>` was treated as a user-created network**: the shared `isUserDefinedDockerNetwork` predicate didn't exclude Docker's `container:` network mode, so the preflight ran `docker network inspect`/`create` against it — Go's `NetworkMode.IsUserDefined()` explicitly excludes `IsContainer()`. Fixed in the shared predicate, so `deploy`/`serve`/`start` get the same fix. - **A repeated `--network-id` flag honored the first occurrence, not the last** — pflag/viper string flags are shared-variable, last-`Set()`-wins (confirmed empirically with a scratch `pflag.FlagSet.Parse` probe). Resolution now goes through `lastExplicitLongFlagValue`, which also handles the `--` terminator and value-consumption cases pflag does. - **`suggestLegacyBundle`'s suggested command wasn't styled**: Go wraps it in `utils.Aqua` (`download.go:315`). Added a `styleAqua` dependency, injected as `legacyAqua` from the legacy handler. - **Malformed function-list entries were silently dropped instead of failing loudly**: a missing/non-string `slug` vanished from the list rather than failing `ValidateFunctionSlug` the way Go's required non-pointer field does. Fixed to preserve the entry (coerced to `""`) so per-slug validation catches it. ## Follow-up parity round (review) Every judgement call previously listed as "left open" on this PR is now closed, in the same shared-layer shape the original notes asked for: - **Shared one-shot docker-run builder**: `buildFunctionsDockerRunArgs` (`functions-docker.ts`) assembles binds/network/env/`-w`/labels for both `deploy`'s bundler and `download`'s unbundler — including Go's unconditional `com.supabase.cli.project`/`com.docker.compose.project` **container labels** (`DockerStart`, `docker.go:349-386`) and the bundler's `WorkingDir` (`bundle.go:79`), neither of which the one-shot containers carried before. - **Live-streamed container output**: `runChildProcess` now tees each decoded stdout/stderr chunk as it arrives (Go's `DockerStreamLogs` behavior) while still accumulating full text for post-exit scans ("invalid eszip v2"). UTF-8 chunk boundaries covered by unit tests. - **ECR→GHCR→Docker-Hub registry retry**: all three `functions` Docker paths (`deploy`/`download`/`serve`) resolve images through `legacyMakeDockerImageResolver` (cache-check every candidate first, then pull with Go's 4s/8s backoff), replacing the single-URL `legacyGetRegistryImageUrl` lookups. - **Go config/dotenv/`Config.Validate` layer**: new `loadFunctionsProjectConfig` (`functions-config.ts`) + `legacyFunctionsGoConfigCompat` run the same `legacyLoadLocalProjectContext` → `legacyResolveLocalConfigValues` pipeline `start`/`stop`/`status` share. Template defaults + `SUPABASE_EDGE_RUNTIME_DENO_VERSION` (ambient or `supabase/.env`) now apply with no `config.toml` on disk; `project_id = ""` fails up front with Go's exact "Missing required field in config: project_id"; project dotenv is threaded into registry resolution (`SUPABASE_INTERNAL_IMAGE_REGISTRY` from `supabase/.env` works). - **`SUPABASE_NETWORK_ID`**: honored for network selection via `resolveDockerNetworkMode`, preserving viper's exact precedence (a `Changed` pflag — including explicit-empty `--network-id=` — resolves before `AutomaticEnv`). `start`/`db start`'s older resolver contradicted that corner and has been deleted in favor of the shared helper. - **Edge-runtime image tag**: pins from `supabase/.temp/edge-runtime-version` now apply **verbatim** (Go's `replaceImageTag`, `pkg/config/utils.go:81-84`) via a single `edgeRuntimeImage` helper whose default comes from the Go Dockerfile (`dockerfileServiceImage`), fixing the v-double-prefix bug without introducing a new divergence for bare pins like `latest`, and eliminating the drift risk of `@supabase/stack`'s separately-maintained version catalog. `serve.ts`'s own pin lookup (stale `v1.74.2` default, different prefix handling) is folded into the shared helpers. - **Styled "Docker is not running" warning**: `WARNING:` renders through an injected `styleWarning` (Go's `utils.Yellow`) in both shells' `deploy`/`download`. - The stale older "Functions" section in `docs/go-cli-porting-status.md` is rewritten. A post-round go-parity-auditor + engineer-review pass over this work found and fixed: the config layer initially returning the validation-only project id (bypassing the `[remotes.<ref>]` OVERRIDE-tier guard for `SUPABASE_PROJECT_ID`), `deploy`'s bundler `--verbose` gating on `--debug` presence instead of `viper.GetBool` semantics (`--debug=false`), unsanitized `next`-shell project ids reaching container labels, and per-invocation spawn finalizers accumulating across `functions serve` restarts (`runChildProcess` is now self-scoped). **Known divergences deliberately left, documented at the code site**: `serve`'s container/network names don't see a project-dotenv-only `SUPABASE_PROJECT_ID` (reconciling its `projectIdOverride` precedence risks a regression in `start`'s shared bring-up core); `serve` resolves/pulls the image before `--env-file` parsing where Go parses first (UX-only: same error, later); an ambient `SUPABASE_EDGE_RUNTIME_DENO_VERSION` can still beat a matched `[remotes.<ref>]` block's `deno_version` (computing override keys needs the db-toml remote pipeline this path doesn't run). ## Refactoring - Hoisted the Docker-orchestration primitives `download.ts` needs out of `deploy.ts` into `shared/functions/functions-docker.ts`, per this workspace's "Hoist Before You Duplicate" policy — `deploy.ts`, `serve.ts`, and `legacy/shared/db-bootstrap/container-lifecycle.ts` now import from the new module. - Deduplicated the `edge-runtime-version` pin-file lookup (previously copy-pasted across all four `deploy`/`download` handler files, plus `serve`'s divergent copy) into `resolveEdgeRuntimeVersionPin`/`edgeRuntimeImage` in `functions.shared.ts`. - Consolidated `--network-id` resolution to one home (`resolveDockerNetworkMode`), deleting `legacyResolveNetworkId` and the weaker `explicitStringFlag`/`hasGlobalLongFlag` argv scanners in favor of the existing, stronger `lastExplicitLongFlagValue`/`explicitBooleanLongFlag`.
## What kind of change does this PR introduce? Docs update (ADR + agent guide). ## What is the current behavior? `apps/cli/AGENTS.md` reads, top to bottom, as porting-era guidance: it opens with the Phase 0/1 wrapping workflow and states unconditionally that `apps/cli-go/` is "the authoritative source" for anything touching `src/legacy/`. That was correct while the legacy shell was being built from scratch, but the port is now largely done — 95 of 103 legacy leaf commands (~92%, per `apps/cli/docs/go-cli-porting-status.md`) are natively ported, with only 8 remaining Phase 0 proxies. Agents (and humans) doing net-new work in `src/legacy/` — bug fixes, refactors, TS-only additions, tests — keep following the unconditional framing literally and audit Go source, or judge review feedback against Go parity, for changes that have nothing to do with it. ## What is the new behavior? - Adds **ADR 0016** recording the decision and its rationale, and indexes it in `docs/adr/README.md`. - Adds a "Legacy Port Status and Go CLI Authority" section near the top of `apps/cli/AGENTS.md` stating current completion and exactly when `apps/cli-go/` is required reading: finishing one of the remaining wrapped ports, or changing an already-ported command's established parity surface (command/flag names, stdout/stderr text, exit codes, filesystem/API side effects, telemetry payload shape). Everything else in `src/legacy/` is treated like any other TypeScript workspace. - Reframes the "Phase 0: Go Binary Wrapper" section as the exception path for the residual wrapped commands, not the default onboarding workflow. - Adds the same scoping caveat to the "Legacy Port: Go CLI Output Parity" section and the `apps/cli-go/` reference blurb. - Adds a pointer from `go-cli-porting-status.md`'s header to the ADR/AGENTS.md scoping. Companion change (not in this diff, personal Claude Code config): updated the `go-parity-auditor` and `review-adjudicator` subagent definitions to apply the same scoping — parity is the deciding standard only for the two cases above, not for every legacy-shell change.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6dc628a24c
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…emplates with 5 updates (#6158) Bumps the docker-minor group in /apps/cli-go/pkg/config/templates with 5 updates: | Package | From | To | | --- | --- | --- | | postgrest/postgrest | `v16.0` | `v16.1` | | supabase/postgres-meta | `v0.96.8` | `v0.97.0` | | supabase/realtime | `v2.124.3` | `v2.124.4` | | supabase/storage-api | `v1.68.15` | `v1.69.0` | | supabase/logflare | `1.50.1` | `1.50.2` | Updates `postgrest/postgrest` from v16.0 to v16.1 Updates `supabase/postgres-meta` from v0.96.8 to v0.97.0 Updates `supabase/realtime` from v2.124.3 to v2.124.4 Updates `supabase/storage-api` from v1.68.15 to v1.69.0 Updates `supabase/logflare` from 1.50.1 to 1.50.2 Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## TL;DR moves the 47 docs ref(s) from `apps/cli-go/docs/` to `apps/cli/docs/` because we are deprecating/moving away from GO-CLI in M9... the upcoming ts docs spec generator will read them from the *this* new location, nothing consumes it yet and the Go originals are untouched. The copies differ from the originals only by oxfmt whitespace and list marker normalization required by this workspace's format check... ## ref: - towards: CLI-2171
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
…ocation (CLI-1968) (#6150) ## What changed Ports the `db diff --use-pgadmin` engine from delegating the whole invocation to the bundled Go binary to a native TypeScript implementation: - **`legacy-pgadmin-diff.ts`** (new): the differ-container loop (one `supabase/pgadmin-schema-diff:cli-0.0.5` run, or one per `--schema`, with Go's exact argv/env/network/labels/extraHosts) plus pure ports of Go's `ProcessDiffOutput` (JSON diff filtering: type whitelist, extension-dependency skip, `InternalSchemas` exclusion, pgAdmin header assembly) and `ProcessDiffProgress` (stderr `%`-regex → status lines, including Go's greedy-submatch and `.`-matches-`\r` semantics via the `s` flag). - **`diff.handler.ts`**: the pgadmin branch now runs natively — `AssertSupabaseDbIsRunning` parity check → native shadow (CLI-1956 primitives, `acquireUseRelease`) → differ run → the shared SaveDiff tail (`No schema changes found` at `len < 2`, `--file` migration write + warning, stdout print). `rebuildDelegateArgs` became the pg-schema-only `rebuildPgSchemaDelegateArgs`: **`--use-pg-schema` is now the sole remaining Go delegation on `db diff`** (CLI-1960). - Two new error classes with error-actionability metadata; SIDE_EFFECTS.md rewrite; porting-status + binary-distribution doc flips. ## Why Part of M9 (Go removal). Unlike `--use-pg-schema` (in-process `stripe/pg-schema-diff` Go library — documented keep-in-Go exception), the pgAdmin engine was never Go-bound: it is a plain container invocation plus pure output post-processing. Its only real blocker was native shadow provisioning, which landed in CLI-1956 (#6027). ## Reviewer-relevant context - **Deliberate divergence — do not "restore parity" here.** Go's `DiffStream` uses value receivers (`internal/utils/container_output.go:79,87`), so `Collect()` always reads an empty buffer: the Go CLI's `--use-pgadmin` has always printed `No schema changes found` (exit 0), never written a migration file, and can never hit a JSON parse error (verified empirically against Go 1.26). This port implements the intended algorithm instead; the ruling is recorded in `SIDE_EFFECTS.md` ("Deliberate divergence") and as a comment on CLI-1968. - **Network static ruling**: on the default project bridge network, neither of Go's `127.0.0.1` URLs is reachable from the differ container — identically in both implementations (same argv/network → same outcome). `--network-id host` alone doesn't rescue it either (it also rewires the shadow, discarding its port publication); both databases are reachable only with host networking plus a contrived `shadow_port = 5432` override — identically on both binaries — which is exactly where the divergence above becomes user-visible. A gated live scenario was added to `diff.live.test.ts` (not executed in CI). - Reviewed by a Go-parity audit (container argv/URLs/filter chain/error text verified against Go source and empirical Go runs, including `encoding/json` acceptance rules and `strings.TrimSpace` Unicode semantics) and an engineer review; all findings applied — notably: `/s` regex flag, type predicates instead of an `as` cast, a 3-way docker error-reason mapping (`image_inspect`), machine-mode status lines redirected to stderr instead of dropped, restored child-telemetry assertions on the surviving pg-schema delegation, and `legacyTrimGoSpace` hoisted to `commands/db/shared/legacy-go-string.ts`. - Tests: 53 unit + a full pgadmin integration block (exact argv/image/labels/network, all filter branches, text/json/stream-json, delegation-removal regression guards). Branch coverage on the new code is 100% except two provably unreachable defensive fallbacks (documented). - Merge-order note: #6151 (CLI-1969) moves `legacy-pg-dump.env.ts` (this PR imports `LEGACY_INTERNAL_SCHEMAS` from its current path) — whichever merges second needs a one-line import-path fix. Fixes CLI-1968
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
## What changed
Rewrites `migration squash` from a Go-proxy wrapper into native
TypeScript — the last `LegacyGoProxy` use in the migration family:
- **`squash.handler.ts`** (full rewrite): version validation (bare
`invalid version number`, Go's non-repair-wrapped form) → shadow DB
(create → health-wait → connect → `SetupDatabase`, deliberately
*without* the `contrib_regression` template, matching Go) → before/after
`auth`+`storage` schema dumps → apply migrations → full-schema dump
rewritten into the last migration file (single `O_TRUNC` open, Go
parity) + separator + line-by-line diff → merged-file deletion
(non-fatal per file) → local suggestion / remote prompt + history
baseline (`DELETE version <= $1` + `INSERT` in one transaction, matching
`migration repair`'s established shape).
- **`squash.diff.ts`** (new): byte-exact port of Go's `lineByLineDiff` +
`bufio.ScanLines`, unit-tested against Go's own `testdata/` fixtures.
**`squash.dump.ts`**, **`squash.errors.ts`** (error-actionability
taxonomy) round it out.
- **Promotions** per "Hoist Before You Duplicate":
`legacy-pg-dump.{env,run,scripts}.ts` moved `commands/db/shared/` →
`legacy/shared/` (squash is the first cross-family consumer; the
Go-script byte-equality test moved with them), and
`legacyShadowRunInputFromLocalContainerInputs` hoisted into
`shared/db-bootstrap/shadow-database.ts` (re-export shim removed;
diff/pull/pgdelta-cache call sites repointed).
- TS-only additive surface: `--output-format json`/`stream-json` payload
`{ squashedInto, removed, removeFailures, alreadyEarliest, isLocal,
baselinedVersion }` (Go owns no machine output here; `removed` =
successful deletions, `removeFailures` = the rest).
## Why
Part of M9 (Go removal). `migration squash` was the last wrapped
migration command; every building block became available once CLI-1956
(#6027) landed. Going native also dissolves the go-parity-audit §3.4
caveat — the proxy couldn't distinguish "`--local` unset" from
"`--local=false`"; the native command models `--local` with
`Flag.withDefault(true)` exactly like `migration up`.
## Reviewer-relevant context
- **Go-parity audit verdict: parity OK.** Highlights it verified: the
decline-prompt-is-**success** path (exit 0 — opposite of
repair/fetch/down), `Baselining migration history to <v>` printing
*before* `Connecting to remote database...`, resolve-before-validate
ordering, the single-migration no-op with zero Docker work,
leak-on-create-failure parity, the exact three-container pg_dump env
matrix (`EXTRA_FLAGS=--schema=auth|storage` vs `EXCLUDED_SCHEMAS`,
`EXTRA_SED=/^--/d`), and `lineByLineDiff` byte-exact against Go's
goldens plus throwaway `bufio` runs. The explicit baseline transaction
was adjudicated equivalent to Go's `pgx.Batch` (single implicit
transaction either way).
- Engineer review found no production bugs; all its items are applied —
including an ordered `BEGIN/DELETE/INSERT/COMMIT` assertion (an
INSERT-before-DELETE mutation previously shipped green),
workdir-relativized error paths via `legacyRelativizeErrorMessage`, and
the `dbConnection` classification matching `repair`'s identical failure.
- Tests: 16 unit (Go testdata read directly from `apps/cli-go`) + 48
integration + 2 Docker-free e2e; 100% branch coverage on the squash
files; key assertions mutation-tested.
- `go-cli-porting-status.md`: both squash rows flipped to `ported`, and
pre-existing aggregate drift corrected (Database family was recorded
5/19 ported, actually 43/43; Project/Stack Lifecycle 2→4; grand summary
now 51/118 fully ported, 59/118 partial).
- Merge-order note: this PR moves `legacy-pg-dump.env.ts`, which #6150
(CLI-1968) imports from the old path — whichever merges second needs a
one-line import-path fix (both also touch
`tests/helpers/legacy-mocks.ts`, trivially).
Fixes CLI-1969
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
## Summary
A Front support ticket surfaced that we tell users `db push
--project-ref <ref>` works, but the legacy TS shell never accepted the
flag. In the Go CLI the linked-ref override was only reachable via the
`SUPABASE_PROJECT_ID` env var on these commands (Go never registered
`--project-ref` on them); the Effect CLI is explicit about which
commands take which flags, and when groups like `sso` got the flag, the
commands that resolve the linked project ref internally were missed.
This adds an optional `--project-ref` flag ("Project ref of the Supabase
project.") to every legacy command that resolves the linked project ref:
- **db**: push, pull, diff, dump, reset, lint, advisors, query
- **migration**: list, up, down, repair, fetch
- **storage**: ls, cp, mv, rm
- **seed**: buckets
- **inspect**: the full `inspect db` family (24 subcommands via the
shared flag record) and `inspect report`
- **test**: db (including the hidden `db test` alias)
Behavior (uniform across all of them):
- The flag feeds `LegacyProjectRefResolver.loadProjectRef`, keeping the
resolver's existing precedence: **flag > `SUPABASE_PROJECT_ID` >
`supabase/.temp/project-ref`**. With the flag unset, behavior is
unchanged.
- It is threaded into every ref-resolution site per command (direct
`loadProjectRef` calls, the shared `LegacyDbConfigResolver`'s
`linkedProjectRef`, the pooler-fallback path, and pre-connect cache
captures), so the connection, the `[remotes.<ref>]` config merge, the
linked-project cache, and Management API paths can never disagree on the
ref within one invocation.
- It does **not** imply `--linked`. Instead of silently ignoring the
flag on a non-linked target (a footgun on `db reset`/`migration up`),
the command errors: `--project-ref only applies when targeting the
linked project; use it with --linked (not --local or --db-url)`. `db
diff` keeps its explicit-mode exception (`--from/--to linked`) and
rejects the flag with the Go-delegating
`--use-pgadmin`/`--use-pg-schema` engines rather than dropping it.
- Telemetry: the flag is recorded but its value stays redacted (no Go
`markFlagTelemetrySafe` baseline exists for these commands; the nearest
Go registration, `cmd/pgdelta_catalog.go`, is unmarked).
- `adHocProjectRef` deliberately stays unset so credential semantics
match the env-var path (documented in `legacy-db-config.types.ts`).
Intentionally excluded: `projects list` (its soft resolve only marks the
linked row in output — nothing to target), `gen types` (already has
`--project-id` per Go parity), and `db schema declarative sync/generate`
(smart-target auto-detection with different semantics).
Docs updated: `go-cli-porting-status.md` (extra-TS-flag notes across all
touched leaves, plus previously missing `db advisors`/`db query` rows)
and each command family's `SIDE_EFFECTS.md`.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
## Summary - add the @supabase/stack/managed Node and Bun entrypoint backed by a versioned centralized SQLite registry - persist opaque ordinary-workspace identities and UUID-addressed stack state directories - coordinate provisioning, updates, deletion, port ownership, abandoned-operation recovery, tombstones, and metadata pruning - provide an injectable in-memory repository plus acceptance-driven coverage and architecture documentation - defer runtime selection and qualification, credential resolution, and legacy bootstrap composition to later CLI slices; this boundary persists only their selected metadata and opaque references ## Why CLI-2106 establishes the M2 persistence boundary for managed local stacks. It gives later CLI work a runtime-independent source of truth while keeping ordinary project folders limited to a small identity marker and keeping credentials out of the registry. --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
Resolves the deferred hygiene items from the CLI-2106 review cycle (CLI-2174). Follow-up to #6152 (originally stacked on it; rebased onto `develop` after its squash-merge). Supersedes #6163, which GitHub closed during a head-branch rename to the Linear-prescribed name. ## Items 2–5 (original hygiene set) - **Shared atomic claim primitive** (items 2+3): the duplicated temp-write → `link()` → `EEXIST` protocol in `managed/identity.ts` and `StateManager.ts` is extracted into `managed/atomic-claim.ts` as a plain-async primitive; Effect callers wrap it. Each call site keeps its own race semantics (identity re-reads the winning marker, StateManager fails with `StateClaimError`). - **Hardlink-less filesystem fallback** (item 3): when `link()` refuses with `EPERM`/`ENOTSUP` (exFAT, FAT32, some network mounts), the claim falls back to an exclusive `writeFile(..., { flag: "wx" })`, which still settles the race. The link-first rationale and the harmlessness of a SIGKILL-stranded `.tmp.<id>` sibling are documented on the primitive. - **Transaction reentrancy guard** (item 4): `runTransaction` in `managed/sqlite.ts` now refuses a nested call before issuing `BEGIN` — and without issuing `ROLLBACK` — so an inner attempt can never discard the outer transaction's writes. Tracked per handle via a `WeakSet`. - **Coverage-guard comment parsing** (item 5): `error-actionability-coverage.unit.test.ts` strips comments and masks string/template-literal contents (scanning interpolation expressions as code) before looking for error-class definitions, so commented or quoted `class X extends Error` text no longer trips the guard. ## Items 7–12 (Effect-refactor verification follow-ups) - **Explicit closed flag** (item 7): the facade's post-close guard branches on a `closed` flag set by `close()`/`asyncDispose` instead of sniffing "disposed" out of rejection text, so a callback's own rejection is reported as itself. - **Original failure preserved through claim release** (item 8): a new `releasingClaimOnFailure` combinator on the catch paths of `updateStackRecord`/`deleteStack` discards anything the release raises (interruption included) and re-raises the original cause; the interrupt re-raise stays scoped to the recording site. - **Publication-poll runtime guard** (item 9): the poll's final answer is checked at runtime; a bounded schedule ending on `None` dies with a clear message instead of silently yielding `undefined`. - **No fabricated report entries from interrupts** (item 10): the liveness-probe, runtime-inspection, and state-reclamation absorption points re-raise interrupt-only causes instead of recording them. - **Claim-before-mask contract gap documented** (item 11): the provision mask now carries a comment pinning the constraint (sync adapters have no suspension point; the mask must extend over row creation before async repositories become real), cross-referencing the same shape in `deleteStack`. - **`migrateSchema` reuses `runTransaction`** (item 12): migration no longer hand-rolls `BEGIN`/`COMMIT`; it runs on a freshly opened handle before any repository transaction exists, so the new reentrancy guard is not tripped. ## Items resolved without code - **Item 1 (synchronous cold-start WAL retry)**: already fixed on the CLI-2106 branch — WAL conversion now retries via an Effect `Schedule.exponential` instead of a blocking `Atomics.wait`. - **Item 6 (`credentials.*` fixture ownership)**: no existing issue owns credential-reference resolution; proposed CLI-2114 (first CLI slice wiring the managed layer) as the owner on Linear. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
Pins a lesson from the M2 managed-layer cycle in `AGENTS.md`: the layer was first written as a Promise-based core and had to be retrofitted to Effect (CLI-2106/CLI-2174), which resurfaced as blocking waits where a `Schedule` belonged, interruption gaps around resource acquisition, and untyped failures leaking through `Effect.tryPromise`. New policy under the Effect section: write runtime code Effect-native from the start (typed `Data.TaggedError` failures, `Layer`-provided services, `Schedule`-based retries, interruption-safe resource handling); expose Promise facades only at package entrypoint edges; plain async is acceptable only for leaf primitives with no Effect semantics of their own. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d0c2faa742
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…rashes (#6164) Fixes two ENOTDIR crash families, reported as a `supabase start` regression (good on 2.109.1, broken from 2.110.0; hit on supabase/server#111 CI), and makes the import scanner's key matching follow the import-maps spec. ## 1. The functions import walker crashed on directory-shaped resolved specifiers The walker regex-scans function sources for import specifiers (comments included) and used to prefix-match bare import-map keys — both faithful ports of the Go walker (`apps/cli-go/pkg/function/deno.go:113-155`). What regressed is the guard that keeps those quirks harmless: Go drops any resolved specifier whose **final path segment** has no extension (`len(path.Ext(mod)) == 0`), while the port checked for a dot **anywhere** in the path (`!modulePath.includes(".")`). A bare key mapped to a file (`"@supabase/server": ".../dist/index.mjs"`) prefix-matching a longer specifier (`@supabase/server/core` — even one appearing only inside a JSDoc comment) produced `.../index.mjs/core`, which passed the wrong guard and crashed with an unhandled `ENOTDIR: not a directory, lstat ...` from `realpath`. 2.109.1 was immune only because `supabase start` still proxied to the Go binary; the native start (#5847, first shipped in v2.110.0) exposed the walker, which had been live for `functions deploy` since v2.108.0 (#5561). Changes: - The guard now checks the final segment only — verified equivalent to Go's `path.Ext` for dotfiles, trailing dots, empty segments, and no-slash specifiers. - For specifiers that **do** carry a final-segment extension but resolve through a file (reachable via a `/`-suffixed key mapped through a file path), Go aborts (`pkg/function/deno.go:131-136` warn-skips only `os.ErrNotExist`), so the walker now throws `FunctionImportNotDirectoryError` carrying Go's message (`failed to read file: open <path>: not a directory`) instead of the raw Node crash. Warn-and-continue was considered and rejected: it would diverge from Go's exit code on a reachable input. The class is classified `invalidConfig` so telemetry books it as user-fixable configuration rather than an internal panic. - `realpathIfExists` (which feeds the TS-only source-root containment check) and the `skipMissingImportMapTargets` catch now treat ENOTDIR like ENOENT — both are TS-only leniency paths with no Go counterpart. ## 2. Import-map matching now follows the import-maps spec (intentional Go divergence, CLI-2179) Go substitutes **any** key that prefix-matches a specifier (`strings.HasPrefix`, `pkg/function/deno.go:150-155`). The import-maps spec — which Deno and edge-runtime implement — only prefix-matches keys ending in `/`; other keys match exactly, and a `/`-suffixed key whose value doesn't also end in `/` is an invalid mapping and is dropped. The scanner now follows the spec (keys, the value-side normalization rule, and scope-name selection), so it only ever chases paths the runtime can genuinely produce. Go's lax matching is what fabricated the unresolvable `index.mjs/core` family in the first place, and it could also mount/upload files that no import can actually reach at runtime. Observable effect: deploy upload sets and serve/start bind mounts may shrink for import maps that relied on bare-key prefix matching — no runtime-resolvable import is affected, since the runtime never honored those matches. Recorded as an intentional divergence in the porting-status docs and per-command SIDE_EFFECTS notes (ruling: CLI-2179). Unwalkable import-map **targets** (a `/`-suffixed value routed through a file) no longer crash either path: the docker bundling path and the default API upload path both skip them with a `WARN: Skipping import map target that is not a directory` on stderr, and the docker path's walker warnings are now actually surfaced instead of being discarded. ## 3. A file named `supabase` in cwd (or any ancestor) crashed every command at boot — even `./supabase --version` Project discovery probes `<root>/supabase/config.{json,toml}` with `fs.exists`, which only maps NotFound to false; the ENOTDIR surfaced as a BadResource PlatformError before argument parsing. The classic trigger is running `./supabase` next to the downloaded binary. Stat failures now read as "no config here" and the ancestor climb continues, matching Go's `getProjectRoot` (`apps/cli-go/internal/utils/misc.go:216-231`, "Treat all errors as file not exists") — including its debug-logging of the swallowed error. The same treatment applies to the next shell's `.supabase/project.json` ancestor probe and its `local-versions.json` read, and the next shell's project-home **write** path (`.supabase` occupied by a file) now fails with a classified "exists but is not a directory" error instead of a raw defect dump.