apache/superset
50.3
Weak · 26 September 2026
708.1k
lines of production code
TypeScript
with Python
3
measurements over time
What this system is
This system is Apache Superset, an enterprise-grade business intelligence platform for data exploration, visualization, and dashboarding. It provides a comprehensive suite of features including a SQL Lab for ad-hoc querying, a modular plugin architecture for custom visualizations, and robust infrastructure for managing databases, datasets, and semantic layers. The platform supports advanced capabilities such as row-level security, embedded dashboard integration, and real-time collaboration via WebSockets, all underpinned by a modernized, command-driven backend architecture.
How it got here
2015–2020 — Architecture modernization and internationalization
66 changes.
This period focused on modernizing the codebase by migrating to SQLAlchemy 2.0, restructuring core models and connectors into dedicated packages, and establishing Alembic for database migrations. It also introduced comprehensive internationalization support for multiple languages and expanded the REST API surface for managing assets, queries, and reports.
2021–2023 — Command pattern migration and modularization
89 changes.
This period focused on refactoring the Superset backend into a structured command pattern, replacing ad-hoc logic with dedicated command classes for dashboards, charts, datasets, and imports. Concurrently, the frontend was modernized through the creation of reusable UI packages, the introduction of an embedded SDK, and the restructuring of visualization plugins. These efforts were supported by the addition of new features such as Row Level Security, tagging, and internationalization, alongside significant improvements to security and data access controls.
2024–2026 — MCP service and semantic layer expansion
107 changes.
This period focused on integrating the Model Context Protocol (MCP) to enable AI agent interaction with Superset resources, alongside the introduction of a new semantic layer for unified data modeling. The work also included significant architectural improvements such as a new SQL parsing engine, distributed locking, and comprehensive versioning infrastructure for charts and dashboards.
Features
Add Czech (cs) language translations
Users can now see the Superset interface in Czech. This change adds the initial Czech translation file (messages.po) for the application, enabling localization for Czech-speaking users across the UI.
superset/translations/cs · high confidence
Add Docker Nginx configuration for Superset deployment
This change introduces a new Nginx configuration file and a template for Superset's Docker environment. The configuration sets up Nginx to act as a reverse proxy, routing WebSocket connections and static assets to their respective upstream services (superset-node and superset\_app). It also enables Gzip compression for various content types and configures proxy headers to ensure correct request forwarding, supporting deployment under a prefixed URL via the ${SUPERSET\_APP\_ROOT} variable.
docker/nginx · high confidence
Add Finnish (fi) language translations
Users can now see the Superset interface in Finnish. This change introduces a new translation catalog for the Finnish locale, populated with machine-translated strings covering core UI elements, chart configurations, and error messages.
superset/translations/fi · high confidence
Add Latvian (lv) language support
Users can now view the Superset interface in Latvian. This change introduces the initial Latvian translation catalog (messages.po), enabling localized UI text for dashboards, charts, and settings for Latvian-speaking users.
superset/translations/lv · high confidence
Add MCP tools for listing and retrieving role information
This change introduces two new Model Context Protocol (MCP) tools within the \superset/mcp\_service/role\ module: \list\_roles\ and \get\_role\_info\. The \list\_roles\ tool allows administrators to retrieve a paginated list of roles with filtering, searching, and sorting capabilities, while \get\_role\_info\ retrieves detailed information for a specific role by ID, including its assigned permissions. These tools are implemented using Pydantic schemas for request/response validation and leverage the existing \RoleDAO\ for data access, ensuring proper serialization of FAB role objects and handling potential detached instance errors.
_superset/mcp\service/role · high confidence
Add MCP tools for listing and retrieving tag details
The MCP service now exposes two new tools, \list\_tags\ and \get\_tag\_info\, allowing users to query tag metadata via the Model Control Protocol. \list\_tags\ supports filtering, searching, sorting, and pagination to retrieve collections of tags, while \get\_tag\_info\ retrieves specific details for a single tag by its numeric ID. These tools are backed by Pydantic schemas that define the request and response structures, including humanized timestamps and flexible field selection.
_superset/mcp\service/tag · high confidence
Add Māori (mi) language support
Users can now view the Superset interface in Māori. This change adds the Māori translation catalog (mi) to the application, enabling localized text for UI elements, chart labels, and help content for users who select this language.
superset/translations/mi · high confidence
Add Node.js wrapper for Apache Superset MCP service
A new Node.js entry point script (\superset-mcp.js\) has been added to the \superset/mcp\_service/bin\ directory. This script acts as a bridge between npm/npx tooling and the underlying Python-based Model Context Protocol (MCP) server. It enables users to run the Superset MCP service in either stdio mode (for direct integration with tools like Claude Desktop) or HTTP mode (defaulting to port 5008). The wrapper handles environment validation, Python executable detection, and subprocess management, facilitating future distribution via npm.
_superset/mcp\service/bin · high confidence
Add Romanian (ro) language support
Superset now includes a Romanian translation catalog, enabling users to view the interface in Romanian. This change adds the necessary translation files to support the Romanian locale, making the application accessible to Romanian-speaking users.
superset/translations/ro · high confidence
Add Screenshot Infrastructure for MCP Service
The MCP service now includes a dedicated screenshot module, providing the underlying infrastructure to capture visual representations of dashboards or charts. This addition supports the broader MCP implementation by enabling visual data export capabilities within the service.
_superset/mcp\service/screenshot · high confidence
Add Serbian language support (Cyrillic and Latin scripts)
Users can now select Serbian as an interface language, with support for both Cyrillic (sr) and Latin (sr\_Latn) scripts. This change adds the corresponding translation files to the application, enabling localized text for UI elements, chart options, and system messages for Serbian-speaking users.
_superset/translations/sr, superset/translations/sr\Latn · high confidence
Add Tamil (ta) locale translations
Users can now see the application interface in Tamil. This change adds the Tamil language catalog (messages.po) to the translation directory, providing localized strings for UI elements, chart options, and error messages.
superset/translations/ta · high confidence
Add Thai (th) language translations
Users can now see the Superset interface in Thai. This change introduces the initial Thai translation catalog (messages.po), populated with machine-translated strings for UI labels, chart options, and error messages, enabling localization for Thai-speaking users.
superset/translations/th · high confidence
Add Ukrainian (uk) language support
Users can now view the application interface in Ukrainian. This change introduces the initial Ukrainian translation catalog (messages.po) for the superset/translations/uk locale, enabling localized text for UI elements, chart labels, and error messages for Ukrainian-speaking users.
superset/translations/uk · high confidence
Add user listing and retrieval tools to the MCP service
New MCP tools \list\_users\ and \get\_user\_info\ are now available in the \superset/mcp\_service/user\ module, allowing users to query user metadata with filtering, sorting, and pagination. The implementation includes Pydantic schemas for request and response validation, with sensitive fields like email and roles redacted unless the caller has data model metadata access. The tools correctly handle FAB permission registration by using the \get\ method permission instead of the non-existent \read\ permission, and efficiently manage role data to avoid N+1 queries during list operations.
_superset/mcp\service/user · high confidence
Added Catalan (ca) translations
Superset now includes a new Catalan (ca) translation file, enabling users to view the interface in Catalan. This entry adds the initial set of translated strings for various UI components, including chart configurations, dashboard contexts, and error messages.
superset/translations/ca · high confidence
Added DOAP metadata file for Apache Superset
A DOAP (Description of a Project) RDF file has been added to the ASF directory, providing structured metadata for Apache Superset. This file defines project details such as the name, homepage, license (Apache 2.0), description, bug database, mailing list, and programming languages (JavaScript, Python, TypeScript), facilitating better integration with Apache project infrastructure and directory services.
ASF · high confidence
Added Persian (Farsi) language support
Users can now view the Superset interface in Persian (Farsi). This change introduces a new translation catalog for the 'fa' locale, providing localized text for UI elements, chart labels, and system messages, thereby making the application accessible to Persian-speaking users.
superset/translations/fa · high confidence
Added Polish (pl) language translations
Users can now see the application interface in Polish. This change introduces a new translation file (messages.po) for the Polish locale, containing machine-translated strings for various UI elements, chart options, and error messages, enabling localization for Polish-speaking users.
superset/translations/pl · high confidence
Added Portuguese (pt) translation catalog
The Portuguese (pt) translation catalog has been added to the application, providing localized user interface text for Portuguese-speaking users. This new file contains machine-translated strings for various features, including chart configurations (such as histogram cumulative and normalize options), dashboard filters, and error messages, ensuring that these interface elements are displayed in Portuguese.
superset/translations/pt · high confidence
Added Slovenian (sl\_SI) language support
Users can now view the Superset interface in Slovenian. This change introduces the initial Slovenian translation catalog (messages.po), providing localized strings for UI elements, chart controls, and error messages, with the majority of entries generated via automated backfilling to ensure broad coverage.
superset/translations/sl · high confidence
Added Traditional Chinese (zh\_TW) translation support
Users can now select Traditional Chinese as a display language in the application. This change introduces the zh\_TW locale catalog, populated with machine-translated strings for UI elements, chart configurations, and system messages, enabling a localized experience for Traditional Chinese speakers.
_superset/translations/zh\TW · high confidence
Added command to prune expired key-value store entries
A new CLI command has been added to manually clean up the key-value store by deleting entries that have passed their expiration time. This addresses the fact that the metastore backend does not automatically evict expired rows, allowing administrators to free up database space by running this housekeeping task.
_superset/key\value/commands · high confidence
Added quickstart system prompts for MCP service users
The MCP service now includes a new system prompt module that provides tailored onboarding workflows for new users. Based on the user type (analyst, executive, or developer) and focus area, the service guides users through specific sequences of tool calls—such as \get\_instance\_info\, \list\_datasets\, and \generate\_chart\—to help them explore data and create visualizations. The prompts dynamically use the configured application name instead of hardcoding 'Superset'.
_superset/mcp\service/system/prompts · high confidence
Adds CSRF token endpoint, OAuth2 callback template, and core SPA/macros infrastructure
This change introduces several new template files to support security, authentication, and the single-page application shell. It adds a new \csrf\_token.json\ endpoint that returns the CSRF token as JSON, enabling frontend components to fetch the token dynamically. It includes a new \oauth2.html\ template that handles the OAuth2 authorization callback by posting a message via BroadcastChannel and storing completion status in localStorage. Additionally, it adds \macros.html\ to centralize CSP nonce generation and \spa.html\ to serve as the main application shell, which now includes support for mobile consumption mode, Open Graph metadata, service worker registration, and dynamic theme-based loading spinners.
superset/templates/superset · high confidence
Backend command handlers for theme management
This location introduces the backend command-layer logic for managing themes, including creating, updating, and deleting user-defined themes, as well as importing and exporting them. It enforces security by preventing modification of system themes and restricting edits to system-default or system-dark themes to administrators only. The delete command automatically dissociates dashboards from themes before removal, and the import command ensures the importing user becomes the theme editor.
superset/commands/theme · high confidence
Chart commands restructured into a dedicated module with enhanced validation and security
The chart command logic has been reorganized into a new \superset/commands/chart\ package, introducing dedicated command classes for create, update, delete, restore, export, and favorite operations. This change enforces stricter validation: chart creation and updates now require explicit \viz\_type\ fallback handling and validate that query-context-only updates remain bound to the chart's original datasource. Deletion is blocked if associated alerts or reports exist, with clear user-facing messages. Security is tightened by requiring editor access for standard updates while allowing access-only for query-context updates, and by validating dashboard relationships during updates. The export command now supports YAML output with Unicode, tag inclusion, and dataset UUID references.
superset/commands/chart · high confidence
Chart controls package initialization and component restructuring
The \@superset-ui/chart-controls\ package has been initialized with a new changelog and README, establishing the foundation for the chart control library. This change introduces several new React components for the Explore interface, including \CertifiedIconWithTooltip\ for displaying certification status, \ColumnOption\ and \ColumnTypeLabel\ for rendering column metadata with type-specific icons, and \ControlHeader\ and \ControlSubSectionHeader\ for structuring the control panel UI. Additionally, a TypeScript declaration file for \ace-builds\ has been added to support SQL editing capabilities within the controls.
superset-frontend/packages/superset-ui-chart-controls · high confidence
Deletion retention: purge of soft-deleted entities
This change introduces the backend command logic for the deletion retention feature, enabling the scheduled and force-purge of soft-deleted entities. It adds a dedicated \purge\_audit\_log\ table to record purge outcomes (pending, confirmed, blocked, failed) independently of the purge transaction, ensuring audit integrity even if a purge fails. The implementation includes a \ForcePurgeCommand\ for immediate, irreversible removal of entities by UUID, a \purge\_cascade\ module to handle the hard-delete of dependencies (M:N joins, owned children, version history) while preserving independently-owned entities, and a \purge\_policy\ system to declaratively define purge behavior and block reasons for different entity types. It also adds logic to resolve the retention window from configuration or shared values.
_superset/commands/deletion\retention · high confidence
Extensible chart type plugin registry for MCP service
The MCP service now uses a plugin-based architecture to support a wider variety of chart types, including Big Number, Box Plot, Bubble, Gantt, Gauge, Handlebars, Histogram, Interactive Pivot, Mixed Timeseries, Pie, Pivot Table, Table, Treemap, Waterfall, and XY charts. This change introduces a registration system that allows new chart types to be added by implementing a class extending BaseChartPlugin, improving extensibility and maintainability of the chart generation logic.
_superset/mcp\service/chart/plugins · high confidence
Guided chart creation workflow for MCP service
The MCP service now includes a 'create\_chart\_guided' prompt that provides a structured, step-by-step workflow for users to create visualizations. This feature assists users in selecting appropriate chart types (such as line, bar, scatter, area, or table) based on their data and business goals, and guides them through finding datasets, examining columns, configuring chart parameters, and validating results. It also documents available aggregation functions, custom SQL metric syntax, and time grain options to simplify the chart creation process.
_superset/mcp\service/chart/prompts · high confidence
Initial Alembic migration infrastructure setup
The \superset/migrations\ directory now contains the foundational configuration and utilities for database schema management using Alembic. This includes the \alembic.ini\ configuration file, the \env.py\ script that handles migration execution (including logging duration and escaping database URIs), and \migration\_utils.py\ which provides helper functions for creating and dropping unique constraints with specific naming conventions. Additionally, a \script.py.mako\ template is provided to standardize the format of new migration files, and a README explains the single-database configuration.
superset/migrations · high confidence
Initial Arabic (ar) translation support added
Users can now see the Superset interface in Arabic. This change introduces the first Arabic translation catalog (ar/LC\_MESSAGES/messages.po), containing over 22,000 lines of machine-translated strings for UI labels, chart configurations, and error messages, enabling Arabic-speaking users to navigate the application in their native language.
superset/translations/ar · high confidence
Initial Brazilian Portuguese (pt\_BR) translation support
Users can now see the application interface in Brazilian Portuguese. This change adds the initial set of translated strings for the pt\_BR locale, covering core UI elements, chart configurations, and error messages, enabling a localized experience for Portuguese-speaking users in Brazil.
_superset/translations/pt\BR · high confidence
Initial Dutch (nl) translation catalog added
A new Dutch language translation file (messages.po) has been added to the application, providing localized UI text for users. The catalog contains 22,000+ lines of translations, including machine-translated content for complex chart descriptions (such as histogram cumulative and normalize options) and standard interface strings, enabling the application to display in Dutch.
superset/translations/nl · high confidence
Initial English translation file added
The English localization file (messages.po) for the application has been added, providing the base set of translatable strings for the user interface. This file serves as the source for all English text displayed to users, ensuring consistent terminology across the product.
superset/translations/en · high confidence
Initial French (fr) translation catalog added
A new French translation file (messages.po) has been added to the application, providing localized UI strings for the French language. This includes translations for core interface elements, chart configuration help text (such as histogram cumulative and normalize options), and error messages, enabling French-speaking users to interact with the platform in their native language.
superset/translations/fr · high confidence
Initial Italian (it) translation backfill
Added the initial Italian language pack for the Superset interface, providing machine-translated strings for UI elements, chart configurations, and error messages. This enables users to view the application in Italian, covering core features such as dashboard contexts, histogram options, and SQL Lab formatting.
superset/translations/it · high confidence
Initial Japanese language support added
Users can now view the Superset interface in Japanese. This change introduces the \messages.po\ file for the \ja\ locale, providing translations for UI strings, error messages, and chart configuration labels.
superset/translations/ja · high confidence
Initial Korean (ko) translation backfill
The Korean language catalog now includes machine-translated strings for the user interface, covering chart configuration options (such as histogram cumulative and normalize behaviors), dashboard context filters, error messages, and general UI labels. This change enables Korean-speaking users to see localized text in these areas for the first time.
superset/translations/ko · high confidence
Initial MCP service scaffolding and command override
This change introduces the foundational structure for the new Model Context Protocol (MCP) service within Superset. It adds the initial command module, including a specialized \MCPCreateFormDataCommand\ that adapts the standard form data creation logic to use the user ID directly instead of the Flask session ID, ensuring correct context handling for MCP interactions. Additionally, it establishes the directory skeletons and placeholder imports for dashboard and dataset resources and prompts, preparing the codebase for future MCP-specific feature implementations.
(repo-wide) · high confidence
Initial Slovak (sk) translation catalog added
Users can now see the application interface in Slovak. This change adds the \messages.po\ file for the \sk\ locale, providing the initial set of translated strings for UI elements, chart configurations, and error messages.
superset/translations/sk · high confidence
Initial Spanish (es) translation file added
The Spanish language translation file (messages.po) has been added to the project, providing localized strings for the user interface. This file includes translations for various UI elements, such as histogram options (cumulative, normalize), dashboard filters, and SQL Lab instructions, enabling Spanish-speaking users to interact with the application in their native language.
superset/translations/es · high confidence
Initial Turkish (tr) language support added
Users can now see the Superset interface in Turkish. This change introduces the initial Turkish translation catalog (messages.po), enabling localized text for UI elements, chart configurations, and system messages for Turkish-speaking users.
superset/translations/tr · high confidence
Initial release of @superset-ui/core changelog
The package @superset-ui/core now includes a CHANGELOG.md file that documents its version history, starting with version 0.20.0. This changelog records the addition of new features such as an LRU cache, various extension points for the UI, and new chart visualizations (ECharts Heatmap, Histogram, deck.gl Heatmap), alongside numerous bug fixes for dashboard filters, chart rendering, and data handling.
superset-frontend/packages/superset-ui-core · high confidence
Initial support for Hive database integration
Added the necessary configuration files and scripts to run a local Hive environment for development and testing. This includes a Docker Compose setup defining Hadoop NameNode, DataNode, Hive Server, and Hive Metastore services, along with environment variables for PostgreSQL-based metastore connectivity and a startup script to initialize the Hive warehouse directory.
scripts/databases · high confidence
Introduce Apache Superset Extensions CLI for extension development
The \superset-extensions-cli\ package is now available to scaffold, build, validate, and bundle Superset extensions. It provides commands to generate project structures with optional frontend (React/TypeScript via Webpack Module Federation) and backend (Python) components, enforce naming conventions, and package extensions into distributable \.supx\ files. The CLI requires Python 3.11+ and npm 10.8.2+, and includes a development mode for hot-reloading frontend assets during extension creation.
superset-extensions-cli · high confidence
Introduce Apache Superset MCP Service for AI Agent Integration
This change introduces the Model Context Protocol (MCP) service for Apache Superset, a standalone FastMCP server that enables AI agents to programmatically interact with dashboards, charts, datasets, and SQL Lab. The service provides a comprehensive set of tools for listing and managing resources, generating and updating visualizations, executing SQL queries, and managing instance metadata. It supports multiple authentication methods including JWT tokens, API keys, and a development mode, while enforcing Superset's existing RBAC and Row-Level Security (RLS) policies. The service includes middleware for logging, error handling, response size guarding, and caching, and is designed to run as a separate process sharing the Superset database.
_superset/mcp\service · high confidence
Introduce Cartodiagram plugin to embed charts on a map
Adds the \plugin-chart-cartodiagram\ plugin, which allows users to display existing Superset charts (such as pie or line charts) at specific geographic locations on an OpenLayers map. The plugin requires a dataset with a geometry column containing GeoJSON Point strings and provides configuration options for map layers (WMS, WFS, XYZ), chart sizing per zoom level, and background styling. It includes a control panel for selecting the embedded chart type and map extent, along with Storybook stories for development and demonstration.
superset-frontend/plugins/plugin-chart-cartodiagram · high confidence
Introduce Global Task Framework command layer
This change adds the command-layer implementation for the new Global Task Framework (GTF) in \superset/commands/tasks\. It introduces a unified set of commands to manage task lifecycles: \SubmitTaskCommand\ for creating or joining tasks with deduplication and distributed locking, \CancelTaskCommand\ for aborting or unsubscribing from tasks, \UpdateTaskCommand\ for general task updates with permission checks, and internal commands (\InternalUpdateTaskCommand\, \InternalStatusTransitionCommand\) for efficient, race-safe status and property updates by the framework executor. It also includes \TaskPruneCommand\ for database retention management and \ReapOrphanedTasksCommand\ to recover tasks abandoned by dead workers. These commands provide the core behavioral logic for submitting, monitoring, and managing asynchronous tasks within the new framework.
superset/commands/tasks · high confidence
Introduce Global Task Framework for async operations
Superset now includes a new Global Task Framework (GTF) located in superset/tasks, providing a unified system for managing asynchronous background jobs. This framework introduces a dedicated REST API for task management (including status tracking and cancellation), ambient context management for accessing task state within execution, and specific implementations for async chart queries with per-tab subscription policies. It also replaces the legacy cache warmup strategies with a new task-based approach and adds a scheduled task for purging soft-deleted entities based on retention policies.
superset/tasks · high confidence
Introduce Handlebars chart plugin for custom HTML rendering
Users can now add a Handlebars chart to dashboards, allowing them to write custom Handlebars templates and CSS styles to render query data as arbitrary HTML. The plugin supports two query modes—Aggregate and Raw—and provides built-in helpers for formatting dates, numbers, and JSON, as well as grouping and math operations. The control panel includes editors for the template and styles that adapt to the application's theme, and the rendered output is safely sanitized via the configured HTML sanitization settings.
superset-frontend/plugins/plugin-chart-handlebars · high confidence
Introduce MCP dashboard service implementation
Adds the initial implementation of the dashboard module for the MCP service, including Pydantic schemas for serializing dashboard data, validation logic for dashboard layouts, helpers for resolving dashboard permalinks, and shared constants for grid and ID generation.
_superset/mcp\service/dashboard · high confidence
Introduce MCP dashboard tools for management, data access, and layout control
This change adds a comprehensive suite of Model Context Protocol (MCP) tools for interacting with Superset dashboards, located in \superset/mcp\_service/dashboard/tool\. The new capabilities include listing dashboards (\list\_dashboards\), retrieving metadata and layout (\get\_dashboard\_info\, \get\_dashboard\_layout\), and accessing underlying data (\get\_dashboard\_data\, \get\_dashboard\_datasets\). It also introduces mutation tools for creating (\generate\_dashboard\), duplicating (\duplicate\_dashboard\), updating (\update\_dashboard\), and deleting (\delete\_dashboard\) dashboards, as well as managing chart placement (\add\_chart\_to\_existing\_dashboard\, \remove\_chart\_from\_dashboard\) and native filters (\apply\_dashboard\_filters\, \manage\_native\_filters\). Additional tools handle ownership and role management (\manage\_dashboard\_owners\, \manage\_dashboard\_roles\) and certification (\manage\_dashboard\_certification\), with \restore\_dashboard\ and \duplicate\_dashboard\ supporting soft-delete workflows.
_superset/mcp\service/dashboard/tool · high confidence
Introduce MCP tool for generating interactive explore links
This change adds the \generate\_explore\_link\ tool to the MCP service, allowing users to generate URLs to the Superset Explore interface for a specified dataset. The tool validates that the dataset exists and that the user has access, returning a URL along with form data and permalink keys. It supports optional chart configurations for immediate visualization and includes specific error handling for missing datasets or permission issues.
_superset/mcp\service/explore/tool · high confidence
Introduce Pydantic schemas for the Semantic Layer MCP tools
Added the Pydantic data models that define the request and response structures for the new Semantic Layer MCP tools (list\_metrics, get\_table, etc.). This includes the ListMetricsRequest schema with validation to prevent oversized responses when embedding compatible dimensions, the MetricInfo and DimensionInfo models for metadata, and the GetTableFilter schema which enforces time-range parsing rules to reject unparseable values instead of silently matching full tables.
_superset/mcp\_service/semantic\layer · high confidence
Introduce REST API for managing annotation layers
This change adds the backend API infrastructure for the new annotation layers feature. It introduces a new \AnnotationLayerRestApi\ module that exposes CRUD endpoints (create, read, update, delete) for annotation layers, along with the necessary Marshmallow schemas for input validation and SQLAlchemy filters for list view searching. This provides the programmatic interface required for the annotation layers UI components to function.
_superset/annotation\layers · high confidence
Introduce RESTful API and validation for Row Level Security rules
This change introduces the dedicated \superset/row\_level\_security\ module, providing a new RESTful API (\RLSRestApi\) and associated Marshmallow schemas for managing Row Level Security (RLS) rules. The API exposes standard CRUD endpoints for creating, listing, showing, updating, and bulk-deleting RLS filters, including support for related field lookups for tables and subjects. The new schemas enforce stricter validation, specifically rejecting empty or whitespace-only RLS clauses and ensuring that regular filter types are associated with at least one subject, thereby preventing the creation of non-restrictive or misconfigured security rules.
_superset/row\_level\security · high confidence
Introduce SQL Lab MCP service schemas for structured query execution
This change adds the foundational Pydantic schemas for the new SQL Lab MCP (Model Context Protocol) service, defining the request and response structures for executing SQL queries. It introduces \ExecuteSqlRequest\ to handle parameters like database ID, SQL text, limits, timeouts, and template variables, along with \ColumnInfo\ to normalize column metadata (including handling non-standard nullable values) and \ExecuteSqlResponse\ to structure results, including support for multi-statement queries and error reporting. These schemas ensure consistent, validated data exchange between the MCP service and the underlying SQL execution engine.
_superset/mcp\_service/sql\lab · high confidence
Introduce SQL Lab permalink API for persistent query sharing
This change adds the backend API components for SQL Lab permalinks, enabling users to save and retrieve persistent query states. The new \SqlLabPermalinkRestApi\ exposes endpoints to create a permalink (storing the query state in key-value storage and returning a unique key/URL) and to retrieve the state via that key. Supporting files define the data schema (including database ID, SQL text, schema, catalog, and template parameters), custom exception types for invalid or missing states, and type definitions for the stored value structure.
superset/sqllab/permalink · high confidence
Introduce Saved Queries REST API with filtering, export, and import capabilities
This change introduces the backend REST API for Saved Queries, enabling users to manage saved SQL queries via standard CRUD operations. The API supports bulk deletion and export of queries as ZIP archives, as well as importing queries from bundles. It includes specific filters for favoriting, tagging (by name or ID), and full-text search across query metadata, along with validation to reject blank labels and ensure imported files are valid ZIPs.
_superset/queries/saved\queries · high confidence
Introduce Saved Query import command with strict ownership validation
This change adds the \superset/commands/query/importers\ module, providing the infrastructure to import Saved Queries from bundled archives. The new v1 importer (\ImportSavedQueriesCommand\) handles the import of saved queries along with their associated databases. Crucially, the implementation enforces strict ownership checks: users can only overwrite existing saved queries if they are the original creator or an administrator, preventing import bundles from replacing another user's saved queries and ensuring that SQL is executed under the correct user's security context.
superset/commands/query/importers · high confidence
Introduce Table V2 (AG Grid) as a new chart type
Adds a new 'Table V2' chart powered by AG Grid, providing a spreadsheet-like view with advanced features including server-side pagination, column-level filtering, time comparison visibility controls, and zebra striping. The plugin includes a dedicated control panel for configuring query modes (aggregate vs. raw records), percentage metrics, and conditional formatting, along with a custom header component that supports sorting, filtering, and kebab menus.
superset-frontend/plugins/plugin-chart-ag-grid-table · high confidence
Introduce automated database metadata completeness reporting
A new auto-generated report, \METADATA\_STATUS.md\, is now included in the \db\_engine\_specs\ directory to track the completeness of metadata (such as descriptions, categories, and connection strings) across all 79 supported database engine specs. This report, produced by the \lint\_metadata.py\ script, highlights that 64 specs currently have metadata and provides a clear guide for developers to add missing fields to their engine specifications.
_superset/db\_engine\specs · high confidence
Introduce core MCP tool registration and dependency injection
This change adds the foundational Python modules for the Model Context Protocol (MCP) integration within Superset. It introduces a concrete dependency injection implementation and a \@tool\ decorator that registers functions as MCP tools. The decorator handles automatic tool ID prefixing based on the current extension context to prevent collisions, derives output schemas from function return types, and supports optional RBAC permission checking and authentication hooks for registered tools.
superset/core/mcp · high confidence
Introduce dataset MCP service with validation and schema definitions
This change adds the core implementation files for the dataset module within the MCP service, including Pydantic schemas for dataset information, filtering, and column metadata, as well as utility functions for resolving datasets by ID or UUID. The schemas enforce strict validation, such as rejecting unparseable UUIDs in filter values to prevent system errors, and support selective column serialization to optimize response sizes. This provides the foundational data structures and validation logic required for dataset-related MCP tools.
_superset/mcp\service/dataset · high confidence
Introduce dedicated key-value store module for shared state and permalinks
A new \superset.key\_value\ module has been added to centralize storage of shared application state, including dashboard and SQL Lab permalinks, guest token revocation versions, and soft-delete retention settings. This change introduces a structured entity model (\KeyValueEntry\) with support for JSON and Marshmallow codecs, utility functions for generating deterministic UUID keys via configurable hash algorithms (SHA-256 with MD5 fallback), and specific shared entry handlers for managing permalink salts and other global configuration values.
_superset/key\value · high confidence
Introduce entity versioning infrastructure for charts, dashboards, and datasets
This change adds the foundational backend components for a new versioning system, enabling the tracking of historical changes and the restoration of previous states for charts, dashboards, and datasets. The implementation includes a diff engine to generate atomic change records, a capture listener to record these changes on save, and a restore engine to revert entities to earlier versions. It also introduces API helpers and read-side queries to expose version history and activity streams, along with optimistic concurrency controls (ETags) to prevent conflicting edits.
superset/versioning · high confidence
Introduce extensible chart type plugin registry for MCP service
The MCP chart tools now use a centralized plugin registry to manage chart type support, replacing the previous scattered dispatch logic across schema validation, dataset validation, and configuration mapping. This change introduces a \ChartTypePlugin\ protocol and a \BaseChartPlugin\ base class, allowing each chart type (such as XY, Gantt, Gauge, Treemap, and others) to encapsulate its own pre-validation, column extraction, form data mapping, and post-mapping validation in a single module. The registry also supports runtime filtering to enable or disable specific chart types, and lazy-loading ensures plugins are only imported when needed, improving startup performance and modularity for the MCP chart generation workflow.
_superset/mcp\service/chart · high confidence
Introduce modular pandas post-processing operations
The pandas post-processing logic has been refactored from a monolithic structure into a modular package under \superset/utils/pandas\postprocessing\. This change introduces distinct, independently maintained operator modules for specific data transformations, including \aggregate\, \boxplot\, \compare\, \contribution\, \cum\, \diff\, \flatten\, \geography\, \histogram\, \pivot\, \prophet\, \rank\, \rename\, \resample\, \rolling\, \select\, and \sort\. The package centralizes these operations in \\\init\\_.py\, exposing them via a unified \OPERATIONS\ list for chart dispatch and adding a \build\_extra\_ops\_map\ function to support the \EXTRA\_PANDAS\_POSTPROCESSING\_OPS\ extension point for custom user-defined operators.
_superset/utils/pandas\postprocessing · high confidence
Introduce per-resource API key scopes for MCP access
The API key management UI now allows users to assign granular scopes (read/write) to specific resources such as dashboards, charts, and SQL Lab when creating a key. These scopes restrict access to Model Context Protocol (MCP) resources rather than the general REST API, enabling more precise permission control while maintaining legacy RBAC-only behavior if no scopes are selected.
superset-frontend/src/features/apiKeys · high confidence
Introduce semantic layer MCP tools for metric and dimension discovery
This change adds four new Model Context Protocol (MCP) tools to the semantic layer service: \list\_metrics\, \get\_table\, \get\_compatible\_dimensions\, and \get\_compatible\_metrics\. These tools enable programmatic discovery and querying of data sources, supporting both built-in SQL datasets and external semantic views. \list\_metrics\ allows users to retrieve available metrics with optional search and compatible dimension details, while \get\_table\ executes queries against selected metrics and dimensions. The compatibility tools (\get\_compatible\_dimensions\ and \get\_compatible\_metrics\) help clients progressively refine queries by returning only valid dimensions or metrics that can be combined with current selections, ensuring semantic constraints are respected before execution.
_superset/mcp\_service/semantic\layer/tool · high confidence
Introduce semantic layer command handlers with secure configuration masking
This change adds the command-layer implementation for creating, updating, and deleting semantic layers and views. It enforces object-level access checks on all operations and introduces robust masking for write-only configuration fields, ensuring that secret values are hidden in responses and safely round-tripped during updates without exposing stored credentials.
_superset/commands/semantic\layer · high confidence
Introduce semantic layers API and core models
This change adds the backend foundation for the new semantic layers feature. It introduces the \SemanticLayer\ and \SemanticView\ database models, a REST API (\api.py\) for managing these resources, and a configuration masking system (\masking.py\) to securely handle secrets in layer configurations. Additionally, it provides label helpers (\labels.py\) to update UI terminology when the feature is enabled, and a mapper (\mapper.py\) to translate query objects for semantic view execution.
_superset/semantic\layers · high confidence
Introduce standalone WebSocket server with Docker support and configurable connection limits
This change adds the superset-websocket service, a Node.js server that pushes realtime events from the Superset backend to the web frontend. It is containerized via a multi-stage Dockerfile targeting Node 24, and includes a health check endpoint at /health. The server supports configurable per-channel and total connection limits, validates WebSocket upgrade origins against an allowlist, and manages connections using JWT cookies. It is designed to run alongside the main application to handle authenticated realtime sockets.
superset-websocket · high confidence
Introduce streaming CSV export command with context preservation and security fixes
Added a new streaming CSV export command in superset/commands/streaming\_export that enables constant-memory exports for large datasets. This implementation captures and restores Flask's request-scoped context (g) to ensure the acting user is correctly identified during the streaming process, and applies CSV formula-injection escaping to both headers and data values. It also respects the CSV\_EXPORT configuration for decimal separators and delimiters, and ensures SQL query mutators are applied to the streaming connection.
_superset/commands/streaming\export · high confidence
Introduce superset-core package with extension storage and DAO abstractions
The new superset-core package provides the foundational building blocks for Superset backend extensions, including abstract Data Access Objects (DAOs) for core models like Datasets and Databases, and a tiered storage API for extensions. This storage API offers ephemeral (cache-backed) and persistent (database-backed) key-value stores with user-scoped and shared access patterns, along with a dedicated DAO for bulk management of persistent storage entries. The package also includes extension context management and validation constants, establishing the contract for how extensions interact with Superset's core data and state.
superset-core · high confidence
Introduce system tools for the MCP service
The MCP service now exposes a set of system-level tools to help agents interact with the Superset environment. These include \health\_check\ for verifying service status, \get\_instance\_info\ for retrieving instance statistics and activity metrics (with data-model metadata redacted for non-admin users), \get\_schema\ for unified schema discovery across charts, datasets, dashboards, databases, and reports, \find\_users\ to resolve user names to IDs for filtering, and \generate\_bug\_report\ which collects environment details and sanitizes PII and secrets from user-provided context before creating a support report.
_superset/mcp\service/system/tool · high confidence
Introduce system-level MCP service with instance info and user context
The MCP service now includes a new system module that provides tools for retrieving Superset instance metadata (such as counts of dashboards, charts, and databases) and current user identity information. This change introduces Pydantic schemas for serializing instance summaries, recent activity, and user details, along with utility functions to calculate these metrics. It also adds logic to expose the authenticated user's roles and filter capabilities, enabling more context-aware interactions within the MCP environment.
_superset/mcp\service/system · high confidence
Introduce temporary cache REST API
A new REST API for managing temporary cache entries has been added, exposing POST, GET, PUT, and DELETE endpoints. The API accepts JSON values and supports an optional \tab\_id\ query parameter to scope cache entries to specific browser tabs, ensuring that deletions are context-aware. It utilizes JSON key-value encoding and includes schema validation for input values.
_superset/temporary\cache · high confidence
Introduce temporary cache command infrastructure
Added a new command package for managing temporary cache entries, providing abstract base classes for create, read, update, and delete operations. This includes a shared parameters dataclass, specific exception types for cache failures, and an entry model, establishing the foundation for temporary data storage within the application.
_superset/commands/temporary\cache · high confidence
Introduce the Superset Embedded SDK for embedding dashboards
The \superset-embedded-sdk\ directory is now a self-contained sub-project that provides a library for embedding Superset dashboards into external applications via an iframe. The SDK handles guest token authentication (including automatic refresh and timeout protection), manages iframe sandboxing and permissions, and exposes a JavaScript API (\embedDashboard\) that allows host applications to configure the dashboard UI (hiding titles/tabs, controlling filter visibility), pass URL parameters (including initial theme mode), and interact with the embedded dashboard (e.g., setting data masks, getting chart states, customizing permalinks). The package is built with TypeScript, Babel, and Webpack, and is published to npm as \@superset-ui/embedded-sdk\.
superset-embedded-sdk · high confidence
Introduce unified Subject model and read-only REST API for principal management
This change introduces a new \Subject\ model that unifies Users, Roles, and Groups into a single entity, enabling consistent principal management across the platform. A new read-only REST API (\/api/v1/security/subject\) is provided for fetching and filtering these subjects, gated by the \Subject\ permission. The system automatically syncs Subject rows with User/Role/Group changes via database hooks and provides utility functions to manage default viewers for new assets based on creator group membership, supporting the \ASSIGN\_CREATOR\_GROUPS\_AS\_VIEWERS\ feature flag.
superset/subjects · high confidence
Introduce v1 import command infrastructure
A new v1 import command framework has been added to handle asset imports (databases, datasets, charts, dashboards, and saved queries) with improved validation, security, and versioning support. This includes a base ImportModelsCommand for shared logic, an ImportAssetsCommand for general asset imports, and an ImportExamplesCommand for loading example data. Key improvements include stricter security checks for database credentials (ensuring secrets are only re-attached if the connection endpoint matches), support for SSH tunnel credentials during import, automatic transpilation of virtual dataset SQL to the target database dialect, and integration with the new versioning system to track import actions. The framework also handles overwrite confirmation, sparse imports, and better error logging for validation failures.
superset/commands/importers/v1 · high confidence
Introduce write-side change-record capture for charts, dashboards, and datasets
This change adds the \superset.versioning.changes\ package, which implements the write-side infrastructure for tracking granular field-level changes to charts, dashboards, and datasets. It introduces a new \version\_changes\ database table and a session-level listener system that automatically captures diffs of scalar fields and child collections (such as dataset columns and dashboard slice memberships) during save operations. The implementation includes shadow-table queries to resolve historical states, JSON-safety coercion for database values, and support for specific action kinds like restore, import, and clone, laying the groundwork for detailed version history and activity views.
superset/versioning/changes · high confidence
Introduction of Advanced Data Type API and supporting types
This change introduces the initial implementation of the Advanced Data Type (ADT) feature, exposing a new REST API under the \advanced\_data\_type\ module. The API provides two endpoints: \/types\, which returns a list of available advanced data types registered in the application configuration, and \/convert\, which accepts a type and values to translate them into a structured response (including display values and valid filter operators). The implementation includes the \AdvancedDataTypeRestApi\ class, Marshmallow schemas for request validation and response serialization, and Python data structures (\AdvancedDataTypeRequest\, \AdvancedDataTypeResponse\, \AdvancedDataType\) to define the contract for type translation plugins.
_superset/advanced\_data\type · high confidence
Introduction of new dataset, table, and column models
This change introduces new foundational models for datasets, tables, and columns within the Superset application. By establishing these new model structures, the system now has updated internal representations for managing data assets, which serves as the basis for subsequent features or refactoring related to data discovery and schema management.
superset/columns, superset/tables · medium confidence
Introduction of the Explorable protocol for data sources
A new \Explorable\ protocol has been added to define the standard interface for data sources that can be explored to create charts, including SQL datasets, saved queries, and semantic layer views. This protocol establishes a unified contract for metadata (such as metrics and columns) and query execution, ensuring consistent behavior across different datasource types within the Superset explorables module.
superset/explorables · high confidence
MCP service adds instance metadata and schema discovery resources
The Superset MCP service now exposes new system resources to help LLM clients understand the environment and data structures. The \instance://metadata\ resource provides a summary of instance statistics along with lists of available database and dataset IDs, enabling more direct tool usage. Additionally, schema discovery resources (\superset://schema/chart\, \dataset\, \dashboard\, and \all\) are available to provide static metadata about valid columns, sorting options, and search fields for charts, datasets, and dashboards, allowing clients to construct queries without prior API exploration.
_superset/mcp\service/system/resources · high confidence
MCP service introduces common schemas for validation, caching, and pagination
The MCP service adds a shared \common\ module containing Pydantic schemas that standardize request and response structures across tools. This includes \PaginatedListRequest\ and \PaginatedResponse\ for consistent list-tool pagination, \CacheControl\ mixins to leverage Superset's query and metadata caching layers, and \created\_by\_me\/\edited\_by\_me\ filters for user-scoped listings. It also introduces \time\_range\_validation\ to reject unparseable time ranges that would otherwise silently match full tables, and \error\_schemas\ to provide structured, actionable error responses for chart generation.
_superset/mcp\service/common · high confidence
MCP service provides chart configuration examples for LLMs
The MCP service now exposes a new resource at \chart://configs\ that supplies valid \ChartConfig\ examples and templates to large language models. This resource includes working configurations for XY charts (such as line, bar, stacked bar, multi-metric line, scatter, horizontal bar, and stacked area) and table charts, complete with proper schema elements like \ColumnRef\, \FilterConfig\, and \AxisConfig\. By providing these validated examples, the service helps LLMs generate accurate chart definitions that pass schema validation, supporting use cases like time series trends, category comparisons, and correlation analysis.
_superset/mcp\service/chart/resources · high confidence
Migrate SQL Lab to TypeScript
The SQL Lab editor and related components have been converted from JavaScript to TypeScript, improving type safety and developer experience within the SQL Lab interface.
superset-frontend · high confidence
New @apache-superset/core package for building extensions
The new @apache-superset/core package provides the official API surface for building Superset extensions, exposing namespaces for commands, menus, views, editors, chat, and storage. It includes shared UI components like Alert and foundational types for database metadata and error handling, giving extension authors a stable, documented contract for integrating with the host application.
superset-frontend/packages/superset-core · high confidence
New API endpoint for persisting dashboard filter state
A new REST API endpoint has been introduced to store and manage the state of dashboard native filters. This feature allows users to save specific filter configurations (such as time grain, time range, or value selections) to a key-value store, enabling the persistence of complex filter setups across sessions. The implementation includes endpoints for creating, retrieving, updating, and deleting these filter states, ensuring that user-defined filter contexts are preserved and can be restored seamlessly.
_superset/dashboards/filter\state · high confidence
New API endpoint to expose configured webserver domains
A new REST API endpoint at \/api/v1/available\_domains/\ has been added to the backend. This endpoint allows clients to retrieve the list of domains defined in the \SUPERSET\_WEBSERVER\_DOMAINS\ configuration, enabling features like domain sharding for embedded charts.
superset/views · high confidence
New API endpoint to invalidate chart cache records
A new REST API endpoint (\POST /api/v1/cachekey/invalidate\) has been added to the \superset/cachekeys\ module, allowing users to explicitly invalidate cached query results for specific datasources. By providing datasource identifiers (either by unique ID or by database/schema/name), the system locates the associated \CacheKey\ records, removes them from the \data\_cache\ backend (which stores chart query results), and deletes the corresponding database entries. This ensures that subsequent queries for these datasources will fetch fresh data rather than serving stale cached results.
superset/cachekeys · high confidence
New API endpoints for creating and retrieving dashboard permanent links
This change introduces a new REST API module for dashboard permanent links, adding endpoints to create a permalink from a dashboard's current state (filters, active tabs, URL parameters, chart states) and to retrieve that state later. The implementation includes a new \DashboardPermalinkRestApi\ class, Marshmallow schemas for validating the permalink state (including support for null entries in active tabs for legacy v5 imports), and specific exception classes for invalid or failed operations. This provides the backend infrastructure for users to generate and access persistent URLs that preserve the exact configuration of a dashboard view.
superset/dashboards/permalink · high confidence
New API endpoints for viewing report execution logs
This change introduces a new REST API module in \superset/reports/logs\ that exposes report execution logs. It adds endpoints to retrieve a list of logs for a specific report schedule (\/\<pk\>/log/\) and to fetch a single log entry (\/\<pk\>/log/\<log\_id\>\). The API includes schema definitions for OpenAPI documentation and implements base filters to ensure users can only access logs for report schedules they own, mirroring the security model of the main report schedule API.
superset/reports/logs · high confidence
New CRUD REST API for CSS Templates
This change introduces a new REST API for managing CSS templates, enabling users to create, read, update, and delete templates programmatically. The API supports bulk deletion of multiple templates in a single request and includes filtering capabilities to search templates by name or CSS content. This provides the backend infrastructure for managing reusable CSS styles within the application.
_superset/css\templates · high confidence
New CSS Template management modal and tests
Adds the \CssTemplateModal\ component and its associated TypeScript types and unit tests to the \cssTemplates\ feature area. The modal provides a user interface for creating and editing CSS templates, including an Ace-based code editor for the CSS content and a text input for the template name, with validation ensuring both fields are populated before saving. The included tests verify that the editor renders correctly in both Add and Edit modes, that the Name label is properly associated with its input for accessibility, and that the editor state persists correctly during modal open/close transitions.
superset-frontend/src/features/cssTemplates · high confidence
New Calendar Heatmap chart plugin
A new Calendar Heatmap chart plugin has been added to Superset, allowing users to visualize metric changes over time using a color-coded calendar view. This feature includes a React-based component, a control panel for configuring time granularities (domain and subdomain), cell styling, and color scales, along with Storybook stories for development and testing.
superset-frontend/plugins/plugin-chart-calendar · high confidence
New Cursor IDE development standards guide
Added a comprehensive development standards guide for the Cursor IDE that enforces modernization patterns, including a strict ban on JavaScript and Enzyme in favor of TypeScript and React Testing Library, mandates type hints and MyPy compliance for Python, and directs developers to use the @superset-ui/core library instead of direct Ant Design imports.
.cursor · high confidence
New Docker configuration files and helper scripts for development and testing
This change introduces a new set of Docker configuration files and shell scripts to the \docker/\ directory, including \.env\ and \.env-local.example\ for environment variable management, and several new shell scripts (\apt-install.sh\, \docker-bootstrap.sh\, \docker-frontend.sh\, \docker-healthcheck.sh\, \docker-init.sh\, \docker-pytest-entrypoint.sh\, \frontend-mem-nag.sh\, \pip-install.sh\, \tag\_latest\_release.sh\). These files provide a more structured and robust setup for running Superset in Docker, including support for local overrides, frontend building, health checks, database initialization, pytest entrypoints, memory warnings, and package installation. The \.env\ file sets default configuration values, while \.env-local.example\ provides a template for customizing the environment for local development. The shell scripts automate various tasks such as installing system packages, bootstrapping the Python environment, building the frontend, checking health, initializing the database, running tests, and managing release tags.
docker · high confidence
New Docker-based release validation and verification tooling
The RELEASING area now provides a complete set of new scripts and Dockerfiles to streamline and automate the Apache release process. This includes Dockerfiles (Dockerfile.from\_local\_tarball, Dockerfile.from\_svn\_tarball, Dockerfile.make\_docs, Dockerfile.make\_tarball) that build isolated environments using Python 3.11-slim-trixie and Node.js 20.x for building tarballs, generating documentation, and validating release candidates. Supporting scripts include changelog.py for generating structured changelogs from GitHub PRs, generate\_email.py for automating Apache PMC vote and announcement emails, make\_tarball.sh for creating signed source tarballs, set\_release\_env.sh for environment setup, test\_run\_tarball.sh for validating releases in Docker containers, and verify\_release.py for checking SHA512 hashes and RSA/EDDSA GPG signatures against the Apache KEYS file.
RELEASING · high confidence
New Explore Permalink API endpoints for creating and retrieving chart states
This change introduces the backend API layer for the Explore Permalink feature, adding new REST endpoints to create and retrieve permanent links for chart states. The \ExplorePermalinkRestApi\ class exposes POST \/permalink\ to store chart form data, URL parameters, and stateful table configurations (such as column filters and sorting) via \ExplorePermalinkStateSchema\, and GET \/permalink/\<key\>\ to retrieve the stored state. The implementation includes specific exception handling for access denials, not found errors, and template issues, ensuring that users can reliably save and restore their exploration context through the API.
superset/explore/permalink · high confidence
New GitHub Codespaces development environment with optional MCP support
Developers can now launch Apache Superset directly in GitHub Codespaces using a new set of configuration files in the .devcontainer directory. The setup provides a pre-configured Python 3.11 environment with Docker-in-Docker, Node.js 20, and essential system libraries, automatically activating the Python virtual environment and installing pre-commit hooks on container creation. It includes scripts to build the container image, set up dependencies via uv, and start the Superset services using docker-compose-light. An optional 'with-mcp' configuration is also provided, which enables the Model Context Protocol service on port 5008 alongside the main application on port 9001.
.devcontainer · high confidence
New Import/Export REST API endpoints
This change introduces the \superset/importexport\ package, providing new REST API endpoints for exporting all Superset assets (databases, datasets, charts, dashboards, saved queries) into a ZIP bundle and importing them back. The export endpoint generates a timestamped ZIP file containing YAML representations of all assets. The import endpoint accepts a ZIP or JSON bundle and supports advanced features including providing passwords for databases and SSH tunnels, handling masked encrypted extra secrets, performing sparse updates, and controlling whether existing assets are overwritten.
superset/importexport · high confidence
New MCP tools for SQL Lab execution, saving, and context opening
This change introduces three new Model Context Protocol (MCP) tools in the SQL Lab module: \execute\_sql\ for running SQL queries with security validation and DDL blocking, \save\_sql\_query\ for persisting queries as named SavedQueries, and \open\_sql\_lab\_with\_context\ for generating pre-filled SQL Lab URLs. These tools allow AI agents to interact with Superset's SQL capabilities programmatically while respecting existing RBAC permissions and database access controls.
_superset/mcp\_service/sql\lab/tool · high confidence
New MCP tools for chart management and data retrieval
This change introduces a new set of Model Context Protocol (MCP) tools in the \superset/mcp\_service/chart/tool\ directory, enabling programmatic interaction with Superset charts. The tools include \list\_charts\ for discovering and filtering charts, \get\_chart\_info\ and \get\_chart\_data\ for retrieving metadata and query results, \generate\_chart\ for creating new chart configurations, \update\_chart\ and \update\_chart\_preview\ for modifying existing ones, \delete\_chart\ and \restore\_chart\ for lifecycle management, and \get\_chart\_sql\ and \get\_chart\_type\_schema\ for introspection. These tools provide a structured API for LLMs and other clients to manage chart assets, execute queries, and handle chart-specific logic like soft deletes and permission checks.
_superset/mcp\service/chart/tool · high confidence
New MCP tools for dataset management and querying
The MCP service now exposes a suite of dataset-focused tools that allow programmatic interaction with Superset datasets. Users can register physical tables as datasets (\create\_dataset\), save SQL queries as virtual datasets (\create\_virtual\_dataset\), and modify saved metrics on existing datasets (\update\_dataset\_metric\). Discovery and retrieval are handled by \list\_datasets\ and \get\_dataset\_info\, while \query\_dataset\ enables direct data retrieval using the semantic layer (saved metrics and dimensions) without requiring a pre-saved chart.
_superset/mcp\service/dataset/tool · high confidence
New MCP tools for listing and inspecting database connections
This change introduces the foundational schemas and structure for new Model Context Protocol (MCP) tools that allow users to list available database connections and retrieve detailed information about specific databases. The \schemas.py\ file defines the request and response models, including \ListDatabasesRequest\ which supports filtering by columns like \database\_name\, \expose\_in\_sqllab\, and \allow\_file\_upload\, as well as \GetDatabaseInfoRequest\ which accepts a database ID or UUID. The \DatabaseInfo\ schema exposes connection properties such as backend type, SQL Lab exposure, and various execution permissions (CTAS, CVAS, DML, file upload), while also handling field filtering and user directory privacy via \filter\_user\_directory\_fields\. This provides the data contract for the \list\_databases\ and \get\_database\_info\ tools.
_superset/mcp\_service/database, superset/mcp\service/database/tool · high confidence
New MCP tools for listing, viewing, and creating Superset themes
The \superset/mcp\_service/theme\ module introduces three new FastMCP tools—\list\_themes\, \get\_theme\_info\, and \create\_theme\—that allow agents to discover, inspect, and create Superset themes (antd design-token configurations). \list\_themes\ supports filtering, searching, and pagination to find existing themes, while \get\_theme\_info\ retrieves detailed metadata for a specific theme by ID or UUID. \create\_theme\ enables the creation of new themes by accepting a name and an antd design-token configuration (as a JSON object or string), which is validated and persisted using the same command logic as the REST API.
_superset/mcp\service/theme · high confidence
New MCP tools to list and retrieve Row Level Security filter details
The MCP service now exposes two new tools, \list\_rls\_filters\ and \get\_rls\_filter\_info\, allowing administrators to query Row Level Security (RLS) configurations. These tools enable listing RLS filters with pagination, sorting, and column selection, as well as retrieving specific filter details by ID, including associated tables and subjects. Access is restricted to non-guest users to prevent exposure of sensitive security clauses.
_superset/mcp\service/rls · high confidence
New MCP tools to list and retrieve annotation layers and annotations
The MCP service now exposes four new tools for exploring Superset annotations: list\_annotation\_layers, get\_annotation\_layer\_info, list\_layer\_annotations, and get\_layer\_annotation\_info. These tools allow users to discover annotation layers and their metadata, list annotations within a specific layer with filtering, search, and pagination, and retrieve detailed information for individual layers or annotations. The implementation includes Pydantic request/response schemas, serialization logic, and error handling, scoped to the annotation\_layer module.
_superset/mcp\_service/annotation\layer · high confidence
New MCP tools to list and retrieve async task details
This change introduces two new Model Context Protocol (MCP) tools for managing async tasks: \list\_tasks\ and \get\_task\_info\. The \list\_tasks\ tool allows users to query a paginated list of tasks with filtering (by task\_type, status, scope), searching, and sorting, while respecting user permissions (non-admins see only subscribed tasks). The \get\_task\_info\ tool retrieves detailed information for a single task using either its numeric ID or UUID. These tools are backed by new Pydantic schemas in \superset/mcp\_service/task/schemas.py\ and utilize the existing \TaskDAO\ for data access.
_superset/mcp\service/task · high confidence
New MCP tools to list and retrieve query history and saved queries
The MCP service now exposes four new tools—\list\_queries\, \get\_query\_info\, \list\_saved\_queries\, and \get\_saved\_query\_info\—allowing LLM clients to browse and inspect SQL query history and saved queries. These tools support filtering, search, pagination, and column selection, and return details such as SQL text, execution status, timing, row counts, and error messages. The \get\_saved\_query\_info\ tool accepts both numeric IDs and UUIDs, while \get\_query\_info\ uses numeric IDs; both require prior use of their respective list tools to discover identifiers.
_superset/mcp\_service/query, superset/mcp\_service/saved\query · high confidence
New MCP tools to list and retrieve report details
The MCP service now exposes two new tools, \list\_reports\ and \get\_report\_info\, allowing users to query alert and report schedules via the API. \list\_reports\ supports filtering, searching, and pagination to retrieve a list of reports, while \get\_report\_info\ fetches detailed metadata for a specific report by its numeric ID. These tools are gated by the \ALERT\_REPORTS\ feature flag and include privacy controls that automatically strip user directory fields from the response.
_superset/mcp\service/report · high confidence
New Query History REST API v1 endpoints
The \superset/queries\ module now exposes a dedicated REST API (v1) for managing query history, replacing the previous implementation. This new API provides endpoints to list queries, retrieve details, and stop running queries, with support for filtering by user, database, and status, as well as sorting by duration and other fields. It also includes a specific endpoint to fetch queries updated since a given timestamp, enabling efficient client-side polling for query status changes.
superset/queries · high confidence
New REST API for managing annotation layers and annotations
This change introduces the backend API infrastructure for the new annotation layers feature. It adds a dedicated \AnnotationRestApi\ class that exposes CRUD endpoints for creating, reading, updating, and deleting annotations, along with bulk deletion support. The implementation includes Marshmallow schemas (\AnnotationPostSchema\, \AnnotationPutSchema\) to enforce validation rules for required fields like short description, timestamps, and JSON metadata, as well as a custom text search filter to allow users to find annotations by content.
_superset/annotation\layers/annotations · high confidence
New REST API for managing report schedules
This change introduces the backend API layer for the new reports system, providing REST endpoints to create, read, update, and delete report schedules. It includes the necessary SQLAlchemy models, marshmallow schemas for validation, and API filters to enforce ownership and security permissions on report schedules and their execution logs.
superset/reports · high confidence
New REST API for managing the current user profile
A new \CurrentUserRestApi\ endpoint is introduced at \/api/v1/me\ to allow users to retrieve their own profile information and update their first name, last name, or password. The implementation includes strict security measures for password changes: it requires the user to provide their current password to verify identity, hashes the new password using the configured method (defaulting to scrypt), and automatically invalidates all other active sessions for the account upon a successful password update. The API also exposes a dedicated endpoint to fetch the current user's roles and permissions.
superset/views/users · high confidence
New REST API for theme management with input sanitization
A new Theme REST API has been introduced in the superset/themes module, enabling the creation, reading, updating, and deletion of themes via standard endpoints. The API includes dedicated methods for setting system default and dark themes, as well as exporting and importing theme bundles. To ensure data integrity and security, the API schemas automatically sanitize theme configurations on input, specifically cleaning SVG content and URLs in brand spinners and validating font URLs, while also enforcing that theme algorithms match the system slot (light or dark) they are assigned to.
superset/themes · high confidence
New React-based Group creation and editing modals
The Group management interface now uses new React components (GroupListModal) for creating and editing groups. This change introduces a unified modal form that handles group name, label, description, role assignment, and user membership, replacing the previous implementation. It includes specific error handling for duplicate group names and utilizes async user selection for adding members.
superset-frontend/src/features/groups · high confidence
New React-based role management modals with improved permission search
The role management interface in the frontend has been migrated to React, introducing new modals for adding, editing, and duplicating roles. The edit modal now uses tabs to separate role details, user assignments, and group assignments, resolving previous issues with modal height and user property display. A key improvement is the permissions dropdown, which now supports server-side search and correctly matches raw permission names (e.g., 'stg\_silver') against their displayed labels (e.g., 'stg silver'), preventing valid options from being hidden. The dropdown also sizes itself to its content to prevent truncation of long permission names.
superset-frontend/src/features/roles · high confidence
New SQL dialects for Databend, DB2, Dremio, Firebolt, HANA, OpenSearch, Pinot, StarRocks, and Vertica
Superset now includes dedicated SQL dialects for Databend, DB2, Dremio, Firebolt, SAP HANA, OpenSearch, Pinot, StarRocks, and Vertica, alongside a PostgreSQL DATE\_TRUNC normalizer. These dialects ensure that ad-hoc columns, metrics, and SQL Lab queries are correctly parsed and regenerated for each engine, fixing issues such as incorrect function mappings, identifier casing, and date arithmetic syntax that previously caused execution failures or silent data errors.
superset/sql/dialects · high confidence
New SQL execution engine with async support
Superset introduces a new SQL execution framework located in superset/sql/execution, providing a dedicated SQLExecutor class and Celery-based asynchronous task handling. This new backend supports both synchronous and asynchronous query execution, featuring multi-statement parsing, configurable SQL mutation (SQL\_QUERY\_MUTATOR), disallowed function checks via AST, row-level security transformations, and result caching. The implementation ensures consistent behavior between SQL Lab and the new execution API by sharing statement block building logic.
superset/sql/execution · high confidence
New SQL parsing and normalization module
A new \superset.sql\ package has been introduced, replacing the legacy \sqlparse\-based parsing with a SQLGlot-based engine. This module includes \parse.py\ for SQL parsing, validation, and dialect mapping, and \metric\_normalization.py\ for normalizing custom metric expressions. This change improves SQL parsing accuracy, security, and support for a wider range of database dialects.
superset/sql · high confidence
New SQL syntax validation for Presto and SQLite databases
A new SQL validation framework has been introduced in the \superset/sql\_validators\ module, providing syntax checking capabilities for Presto and SQLite database engines. The \PrestoDBSQLValidator\ validates queries by executing an \EXPLAIN (TYPE VALIDATE)\ statement against the Presto engine, while the \SQLiteSQLValidator\ leverages the external \syntaqlite\ binary to parse and validate SQL syntax. Both validators return structured \SQLValidationAnnotation\ objects detailing errors or warnings, enabling earlier detection of syntax issues in SQL Lab before query execution.
_superset/sql\validators · high confidence
New SQL type definitions for Presto, MSSQL, and currency handling
This change introduces a new \superset/models/sql\_types\ package containing custom SQLAlchemy type definitions. For Presto, it adds \TimeStamp\ and \Date\ types that explicitly cast values to SQL literals (e.g., \TIMESTAMP '...'\) to ensure correct rendering in queries, along with support for \TINYINT\, \INTERVAL\, \ARRAY\, \MAP\, and \ROW\ types. For Microsoft SQL Server, it adds a \GUID\ type to handle \uniqueidentifier\ columns as \CHAR(36)\. Additionally, it introduces a \CurrencyType\ that automatically parses legacy stringified JSON or Python dict representations of currency configurations into proper dictionaries when read from the database.
_superset/models/sql\types · high confidence
New Switchboard library for iframe-host communication
The superset-ui-switchboard package introduces a new utility for communication between embedded iframes and their host window, enabling plugins to share state and send events across the boundary. This library provides a Switchboard class that wraps MessageChannel to allow defined methods to be called remotely (with results returned) and events to be emitted, supporting the embedded-dashboard feature where plugins need to interact with the host environment.
superset-frontend/packages/superset-ui-switchboard · high confidence
New Table chart plugin released as version 0.20.0
The \@superset-ui/plugin-chart-table\ package has been released as version 0.20.0, introducing a new \CHANGELOG.md\ that documents the plugin's history. This release includes a comprehensive set of bug fixes addressing table rendering and behavior, such as enabling keyboard tabbing on sort headers for accessibility, preventing date wrapping, fixing scrollbar overflow issues, and correcting currency formatting in raw mode. It also introduces new features including support for time comparison in tables, the ability to disable HTML rendering in table cells, and a context menu for drill-to-detail actions. Additionally, the release incorporates performance improvements like memoization to reduce unnecessary re-renders.
superset-frontend/plugins/plugin-chart-table · high confidence
New Tags API and backend infrastructure for managing tags and favorites
The superset/tags package now provides the backend foundation for the tagging system, introducing a new Tag REST API (TagRestApi) that supports CRUD operations, bulk creation, and association of tags with dashboards, charts, datasets, and queries. The models define a Tag entity with custom and implicit types, a TaggedObject association table, and a dedicated user\_favorite\_tag\_table to enable users to favorite tags directly from the list view. The API exposes filters for custom vs. system tags and favorite status, while core.py registers SQLAlchemy event listeners to automatically update tag associations when objects are inserted, updated, or deleted.
superset/tags · high confidence
New advanced data type plugins for Internet addresses and ports
Added new advanced data type plugins for 'internet address' (supporting IP and CIDR ranges) and 'internet port' (supporting numeric ports and common service names like HTTP, SSH, etc.). These plugins enable users to filter and query columns storing IP addresses, CIDR ranges, and port numbers using intuitive operators and display values, with the internet address plugin handling numeric and string inputs for IP networks, and the internet port plugin mapping service names to their corresponding port numbers.
_superset/advanced\_data\type/plugins · high confidence
New bulk tagging and tag management UI components
This change introduces the frontend implementation for bulk tagging and tag editing in the Superset UI. It adds a \BulkTagModal\ component that allows users to apply multiple tags to selected resources (such as dashboards) in a single action, including handling API responses for skipped items due to permissions. It also adds a \TagModal\ component for creating and editing individual tags, supporting both create and edit modes with accessible form fields. The \tags.ts\ utility file provides the underlying API client functions for fetching, adding, and deleting tags, while corresponding test files (\BulkTagModal.test.tsx\, \TagModal.test.tsx\) verify the rendering, user interactions, and error handling of these new components.
superset-frontend/src/features/tags · high confidence
New centralized coordination service and realtime websocket transport
This change introduces a new \superset.coordination\ package that provides a unified interface for distributed coordination primitives (pub/sub, key/value, and event streams) backed by Valkey/Redis, along with a reliable await/notify layer for signaling. It also adds a \superset.websocket\ module that handles the realtime push transport, including JWT-based channel identity and connection tokens for authenticated users and embedded guests, enabling targeted and broadcast notifications via the \superset-websocket\ server.
superset/coordination, superset/websocket · high confidence
New centralized export commands for assets and models
This change introduces a new export command structure in \superset/commands/export\, including \ExportAssetsCommand\ and \ExportModelsCommand\. \ExportAssetsCommand\ provides a unified way to export all core assets (databases, datasets, charts, dashboards, saved queries, and tags) in a single operation, generating a \metadata.yaml\ file and ensuring no duplicate files are produced. \ExportModelsCommand\ serves as a base class for individual asset exports, supporting an \export\_related\ flag to control whether related entities are included. This refactors the export logic to be more modular and consistent, replacing ad-hoc export implementations with a standardized command pattern.
superset/commands/export · high confidence
New charts API module and schema definitions
The \superset/charts\ package now includes a new \api.py\ module that exposes the REST endpoints for chart CRUD operations, favorites, exports, and screenshots, alongside a \schemas.py\ module defining the Marshmallow validation schemas for chart requests and responses. This change introduces the backend API surface for managing charts, including support for soft-delete, versioning, and subject-based access control filters.
superset/charts · high confidence
New command-layer implementation for tag management
This change introduces a new set of command classes in superset/commands/tag to handle tag creation, deletion, updating, and export. The implementation adds explicit access validation for tagged objects (dashboards, charts, queries, datasets) to ensure users can only tag resources they have permission to view, and it introduces specific error handling for Jinja template parsing failures during query access checks. It also provides a dedicated export command for tags, aligning with the broader tagging system feature.
superset/commands/tag · high confidence
New command-layer infrastructure for soft-delete, versioning, and subject management
This change introduces a new \superset.commands\ package that centralizes business logic for asset lifecycle and metadata operations. It adds a \BaseCommand\ framework and specific command classes to handle soft-delete workflows (including \PurgeArchivedCommand\ for permanent deletion and \BaseRestoreCommand\ for recovery), version-restore operations (\BaseRestoreVersionCommand\ for charts, dashboards, and datasets), and subject-based access control (helpers for populating and computing editor/viewer lists). The diff also includes exception classes for command-specific errors (e.g., \CommandInvalidError\, \ObjectNotFoundError\) and utilities for handling soft-delete collision guidance and external entity management checks.
superset/commands · high confidence
New common utility modules for dataframes, caching, and time handling
This change introduces a new \superset/common/utils\ package containing four modules: \dataframe\_utils\ (providing \left\_join\_df\, \full\_outer\_join\_df\, \df\_metrics\_to\_num\, and \is\_datetime\_series\), \query\_cache\_manager\ (a new \QueryCacheManager\ class for managing query result caching with fail-open behavior on backend errors), \time\_grain\_utils\ (adding \apply\_time\_grain\_to\_base\_axis\ to propagate time grain overrides to BASE\_AXIS columns), and \time\_range\_utils\ (providing \get\_since\_until\_from\_time\_range\ and \get\_since\_until\_from\_query\_object\ for consistent time range resolution).
superset/common/utils · high confidence
New cross-entity version activity view
A new read-side activity API has been added to display a unified change history across related entities. For dashboards, the view includes edits to the dashboard itself, charts attached during their active windows, and the datasets those charts pointed at. For charts, it shows edits to the chart and its underlying datasets. The implementation introduces synthetic 'starting version' records to represent initial creation, computes per-record impact payloads (affected charts for dataset changes), and enforces visibility filters to redact details of deleted related entities.
superset/versioning/activity · high confidence
New dataset creation and editing UI components
The dataset management interface now includes a new set of React components for creating and editing datasets. The DatasetPanel displays table columns and handles metadata fetching, including OAuth2 retry logic. The EditDataset view introduces a Usage tab alongside existing Columns and Metrics tabs, showing related object counts. The Footer component provides a dropdown for creating datasets with or without immediate exploration, and the Header dynamically updates the title based on the selected table.
superset-frontend/src/features/datasets · high confidence
New dedicated datasets API module with soft-delete and datetime format detection
The \superset/datasets\ package has been restructured into a dedicated module containing a new \DatasetRestApi\ and supporting schemas, filters, and services. This change introduces soft-delete and restore capabilities for datasets, allowing users to archive and recover datasets rather than permanently deleting them. Additionally, a new \DatetimeFormatDetector\ service automatically samples data to detect and store datetime formats for dataset columns, improving query performance and reducing the need for manual format configuration.
superset/datasets · high confidence
New developer tooling and CI scripts
The scripts directory now includes several new utilities: a migration benchmarking tool (benchmark\_migration.py) to measure database migration performance, an environment checker (check-env.py) to validate local software versions, a change detector (change\_detector.py) to gate CI matrix execution based on file patterns, a GitHub workflow canceller (cancel\_github\_workflows.py), and a Cypress test runner (cypress\_run.py) that executes tests with retry logic. Additionally, shell scripts for license checking (check\_license.sh), npm lockfile validation (ci\_check\_npm\_lock\_version.sh), and Docker build configuration (docker-build-extra-flags.sh, docker-build-plan.sh, docker-compose-up.sh) have been added to support CI and local development workflows.
scripts · high confidence
New distributed lock commands with Redis and database backends
Added \AcquireDistributedLock\ and \ReleaseDistributedLock\ commands in \superset/commands/distributed\_lock\ that provide a unified interface for acquiring and releasing distributed locks. The implementation automatically selects the backend based on configuration: it uses Redis (via \CoordinationService\) when \DISTRIBUTED\_COORDINATION\_CONFIG\ is set, otherwise falling back to the \KeyValue\ database table. Both backends support ownership verification via unique tokens to prevent releasing locks held by other processes after expiration, and the database path includes logic to clean up expired entries before acquisition.
_superset/commands/distributed\lock · high confidence
New email templates for Apache release voting and announcements
The release process now uses dedicated Jinja2 templates to automate communication with the community and the Project Management Committee (PMC). A new vote template (\vote\_pmc.j2\) standardizes the call-for-vote email, including links to the release candidate, Git tag, changelog, and updating instructions. A result template (\result\_pmc.j2\) formats the vote outcome, explicitly listing binding, non-binding, and negative votes along with the vote thread link. Finally, an announcement template (\announce.j2\) generates the public release email, providing direct links to the source release, PyPI package, changelog, and update instructions.
_RELEASING/email\templates · high confidence
New embedded dashboard API and view for iframe embedding
This change introduces the core backend components for embedding Superset dashboards in iframes. It adds a new REST API endpoint (\/api/v1/embedded\_dashboard/\<uuid\>\) to retrieve embedded dashboard configuration and a corresponding view (\/embedded/\<uuid\>\) that serves the initial HTML shell. The view enforces security by validating allowed referrer domains and checking the \Sec-Fetch-Dest\ header to ensure the request originates from an iframe or frame context. It also bootstraps necessary configuration, including guest token header settings and allowed domains, into the page for the frontend embedded application.
superset/embedded · high confidence
New extension system with API, caching, and cross-database querying
This change introduces the core backend infrastructure for the new Superset extension system. It adds a REST API (in superset/extensions/api.py) to list and retrieve extension metadata and static assets, along with a WSGI middleware (superset/extensions/cache\_middleware.py) that optimizes asset delivery by stripping the Vary: Cookie header. It also implements a metastore-backed cache (superset/extensions/metastore\_cache.py) for extension state and a native SQLAlchemy dialect (superset/extensions/metadb.py) that allows querying across all configured Superset databases via a superset:// URI.
superset/extensions · high confidence
New headless datasource query API and combined list endpoint
A new REST API has been introduced in the superset/datasource module, providing a headless query endpoint (POST /datasource/\<type\>/\<id\>/query) for executing tabular queries against both SQL datasets and semantic views, alongside a combined list endpoint (GET /datasource/combined/) that aggregates both datasource types into a single response. This change introduces new API schemas (DatasourceQuerySchema, DatasetListSchema, SemanticViewListSchema) and relies on the DatasourceDAO for data access, enabling external clients and internal services to query and discover datasources without using the legacy Explore UI components.
superset/datasource · high confidence
New lightweight Docker development configuration
Developers can now use a simplified Docker Compose setup that removes Redis and Celery dependencies, relying instead on in-memory and filesystem caching. This configuration, along with updated environment variable handling for feature flags and embedded dashboard support, allows for faster, lower-resource local development and testing without requiring a full Redis/Celery stack.
_docker/pythonpath\dev · high confidence
New log retention and pruning command
A new \LogPruneCommand\ has been added to the \superset/commands/logs\ module, allowing administrators to automatically delete old records from the \Log\ table based on a configurable retention period. The command supports an optional \max\_rows\_per\_run\ parameter to limit the number of rows deleted in a single execution, helping to manage database performance and prevent long-running transactions.
superset/commands/logs · high confidence
New script to auto-generate Entity-Relationship Diagrams from SQLAlchemy models
Added a new Python utility in scripts/erd that introspects the application's SQLAlchemy models and generates a PlantUML Entity-Relationship Diagram (ERD). The script groups tables into logical categories (such as Core, System, Data Assets, and SQL Lab) and renders the schema structure, including fields and relationships, into a visual diagram file.
scripts/erd · high confidence
New security module with hardened embedded access and account controls
The superset/security package introduces several new capabilities: it enforces a blocklist of unsafe SQLAlchemy dialects (sqlite, shillelagh, duckdb) to prevent local file access; adds guest-token revocation support with audit logging; implements per-resource API key scopes for MCP tools; enforces optional forced password changes on first use; and applies stricter password complexity policies (minimum length and common-password blocklist).
superset/security · high confidence
New semantic view management modals with server-side hydration
Added the AddSemanticViewModal and SemanticViewEditModal components to the semantic views feature area. The add modal allows users to select a semantic layer and one or more views to create, handling partial success feedback. The edit modal now fetches the view's structure and metadata (description, cache timeout) from the /structure API endpoint on open, ensuring the form reflects the current server state rather than potentially stale props passed from the caller.
superset-frontend/src/features/semanticViews · high confidence
New shared migration utilities and catalog support
This change introduces a new \superset/migrations/shared\ package containing reusable migration utilities and new migration logic for database catalogs. The \utils.py\ module provides helpers for safe column/index checks, dialect-specific UUID generation, and paginated database updates to improve migration performance and reliability. The \catalogs.py\ module adds support for the new \catalog\ column across models like \SqlaTable\, \Query\, and \SavedQuery\, including logic to update and migrate existing data. Additionally, \security\_converge.py\ offers utilities for managing permission views during upgrades, and \constraints.py\ provides a helper to redefine foreign keys with cascading options.
superset/migrations/shared · high confidence
New shared visualization migration framework
A new shared migration infrastructure has been introduced to standardize the conversion of legacy chart configurations to their modern equivalents. This framework provides a base class for defining source-to-target visualization mappings and includes specific migration processors for several chart types, including Pivot Table (v1 to v2), Dual Line to Mixed Chart, and TreeMap. It also introduces logic to handle temporal filter conversions and query context migrations, ensuring that existing charts are correctly updated when imported or when the migration CLI is executed.
_superset/migrations/shared/migrate\viz · high confidence
New superset.common package for chart data and query execution
A new superset.common package has been introduced to centralize chart data and query execution logic. This includes the QueryContext and QueryObject models, a QueryContextProcessor for handling data acquisition and caching, and factories for building query contexts. The package also introduces new enums for chart data result formats (CSV, JSON, XLSX, Arrow) and types (columns, full, query, results, samples, timegrains, post\_processed, drill\_detail), along with timing dataclasses for tracking query performance metrics.
superset/common · high confidence
New translation tooling and CI checks for Superset
This change introduces a suite of scripts in \scripts/translations\ to manage and validate Superset's localization. \babel\_update.sh\ automates the extraction and update of \.po\ files, disabling fuzzy matching to prevent incorrect guesses for new strings and applying a \do-not-translate\ marker to preserve specific msgids. \backfill\_po.py\ provides an AI-assisted tool to generate initial translations for missing entries using Claude, while \build\_translation\_index.py\ creates a cross-language index to support this backfill. To ensure integrity, \check\_pot\_drift.py\ prevents source-template drift, and \check\_translation\_regression.py\ detects regressions by tracking per-string transitions from translated to fuzzy. Finally, \generate\_mo\_files.sh\ compiles the catalogs for the backend.
scripts/translations · high confidence
New utility module for MCP service input sanitization, error handling, and response management
This change introduces a new \superset/mcp\_service/utils\ package containing shared utilities for the MCP service. It adds centralized input sanitization using the \nh3\ library to strip HTML tags and block dangerous URL schemes, preventing XSS and injection attacks. It also includes an error builder and sanitizer that redacts sensitive SQL fragments, schema names, and table identifiers from validation errors to prevent information disclosure, while ensuring control characters are escaped in logs. Additionally, the module provides utilities for managing MCP tool response sizes by measuring exact UTF-8 byte lengths and generating suggestions for reduction, handling cache status extraction and control for query contexts, and supporting flexible JSON string/object input parsing for tool parameters.
_superset/mcp\service/utils · high confidence
New v1 dashboard import command with robust ID remapping
A new v1 import command for dashboards has been added to handle the import process, including the discovery and import of associated charts, datasets, databases, and themes. The implementation includes specific logic to remap internal references during import: it updates chart IDs in filter scopes, timed refresh settings, and expanded slices, and correctly remaps dataset and chart IDs in native filter configurations and display controls. This ensures that imported dashboards correctly reference the newly imported or existing assets rather than stale IDs from the source environment.
superset/commands/dashboard/importers/v1 · high confidence
Point Cluster Map now uses MapLibre with dual-renderer support and improved stability
The Point Cluster Map plugin has been rewritten to use MapLibre as the primary open-source renderer while retaining Mapbox as an optional alternative. This change introduces a new canvas-based rendering engine for point clusters, which improves performance and allows for custom metric labels on clusters. The map now correctly handles the MapLibre worker URL in Webpack bundles, ensuring maps render without errors. Additionally, the plugin now guards against invalid point radii to prevent visual glitches, and preserves OpenStreetMap styles by default. Users can now choose between MapLibre and Mapbox renderers in the control panel, with MapLibre being the default open-source option.
superset-frontend/plugins/plugin-chart-point-cluster-map · high confidence
Re-introduction of the Row Level Security modal UI
The Row Level Security (RLS) feature is restored in the frontend with a new modal interface for managing security rules. This change adds the \RowLevelSecurityModal\ component, along with supporting TypeScript types, constants, and a comprehensive test suite, enabling users to create and edit RLS rules by selecting specific tables and subjects (users/roles) and defining filtering clauses.
superset-frontend/src/features/rls · high confidence
SQL Lab API v1 implementation
SQL Lab now exposes a new REST API v1 (superset/sqllab/api.py) that handles query execution, result retrieval, cost estimation, and formatting. This new API layer introduces stricter security controls, including mandatory dataset matching for raw query access and per-database enforcement of CTAS/CVAS permissions. It also improves template handling by validating Jinja parameters and preventing raw UndefinedError leaks, while supporting both synchronous and asynchronous query execution via Celery.
superset/sqllab · high confidence
SSH tunnel configuration model for database connections
Added the SSHTunnel model to store SSH tunnel settings (server address, port, authentication credentials, and optional host key verification) linked to a specific database. This enables the system to manage and export/import SSH tunnel configurations as part of database connection details.
_superset/databases/ssh\tunnel · high confidence
Semantic layer configuration form and test coverage
This change introduces the frontend implementation for the Semantic Layer configuration modal, allowing users to define and edit layer settings via a JSON Schema-driven form. It includes the \SemanticLayerModal\ component, which handles fetching layer types and configuration schemas, and manages dynamic field dependencies (e.g., clearing dependent fields when a parent changes). The \jsonFormsHelpers\ module provides custom renderers for password, constant, and read-only fields, as well as logic for handling large multi-select catalogs with virtualization. Comprehensive test coverage is added for the modal, the multi-select control, and the helper utilities to ensure correct behavior for schema sanitization, dependency resolution, and UI rendering.
superset-frontend/src/features/semanticLayers · high confidence
Structured Pydantic schemas for Explore link generation
The MCP service now uses explicit Pydantic response schemas for the explore-related tools. The \generate\_explore\_link\ tool returns a structured \GenerateExploreLinkResponse\ containing the generated Explore URL, the underlying form data, and durable permalink keys for sharing, while also providing a typed \ChartGenerationError\ for failures. This allows users and automated clients to reliably parse success and error states (such as dataset not found or permission denied) without relying on free-text message parsing.
_superset/mcp\service/explore · high confidence
Support for custom HTML and JavaScript injection in views
Two new template files, head\_custom\_extra.html and tail\_js\_custom\_extra.html, have been added to the templates directory. These files are included in every Superset view, allowing administrators to inject custom frontend code (such as analytics scripts) into the HTML head or before the closing body tag by overriding these specific templates in their deployment.
superset/templates · high confidence
Theme modal and API now support system theme assignment and algorithm conflict detection
The theme management UI and its underlying API layer now allow administrators to designate specific themes as the system-wide default or dark mode defaults via new API endpoints (\set\_system\_default\, \set\_system\_dark\, and their unset counterparts). To prevent visual mismatches, the theme modal includes validation logic that detects when a theme's declared algorithm (e.g., 'dark') conflicts with the system slot it is assigned to (e.g., the light slot), alerting users that the theme's authored colors may not be displayed as intended.
superset-frontend/src/features/themes · high confidence
Removals
Removal of legacy Panoramix templates
The base layout and datasource view templates for the Panoramix Druid UI have been deleted. This removes the previous Bootstrap-based navigation, styling, and form structures used for datasource interaction and data display.
templates · high confidence
Removal of legacy static assets
The static files for Bootstrap 3, Select2 (v3 and v4), and the application's custom main stylesheet have been removed from the repository. This cleanup eliminates the legacy UI dependencies and custom styling rules that were previously served from the static directory.
static · high confidence
Security
Secure SQL Lab permalink storage and retrieval
SQL Lab permalinks are now stored and retrieved via a secure key-value system using salted hash IDs instead of sequential database keys. This change prevents users from enumerating or accessing other users' saved editor states (including SQL text and connection context) by guessing or incrementing ID values, ensuring that only valid, salted permalink keys can resolve shared queries.
_superset/commands/sql\lab/permalink · high confidence
Secure dataset import with strict URI validation and peer verification
The dataset import command now enforces stricter security checks on data sources. It validates that any HTTP/HTTPS URIs resolve to publicly routable hosts and validates redirect targets to prevent bypasses. Local file:// URIs are restricted to the bundled examples folder. Additionally, the import process now correctly handles database dependencies by importing related databases first and mapping their IDs, ensuring datasets are linked to the correct parent database during import.
superset/commands/dataset/importers/v1 · high confidence
API
Introduce new v1 Database REST API
The \superset/databases\ package now provides a new v1 REST API for managing database connections, replacing the legacy endpoints. This change introduces a dedicated \DatabaseRestApi\ class with explicit CRUD, import/export, and connection-testing endpoints, alongside new marshmallow schemas for validation, decorators for table-access checks, and utility functions for safe URL handling and metadata retrieval. Users interacting with the database management interface will now use the v1 API paths, which offer stricter parameter validation and improved error handling for database operations.
superset/databases · high confidence
New Explore Form Data API endpoints
This change introduces a new REST API for managing explore form data, exposing POST, PUT, and GET endpoints at /explore/form\_data. Users can now create, update, and retrieve form data configurations via the API, with support for datasource\_id, datasource\_type, chart\_id, and tab\_id parameters. The API includes proper validation schemas and handles errors such as validation failures, temporary cache access issues, and template exceptions.
_superset/explore/form\data · high confidence
New Explore REST API endpoint for unified context retrieval
The Explore module now exposes a dedicated REST API (\/explore\) that assembles the initial context (form data, slice, and dataset information) in a single call. This endpoint supports loading context from a cache key, a permalink key, or by directly specifying datasource and slice identifiers, providing a more efficient and unified way for clients to initialize the Explore interface compared to previous multi-step approaches.
superset/explore · high confidence
Architecture
Centralize application initialization in a dedicated module
The application startup logic has been refactored into a new \superset/initialization\ package, consolidating the \SupersetAppInitializer\ class and related setup routines. This change improves code organization by separating initialization concerns from the main application entry point, ensuring that database connections, Celery configuration, and view registrations are handled in a structured, modular manner.
superset/initialization · high confidence
Core API dependency injection mechanism introduced
A new dependency injection system has been added to the core API layer, allowing abstract data access objects (DAOs), models, and query functions defined in superset-core to be replaced with concrete Superset implementations at runtime. This change enables the core API modules to remain loosely coupled while integrating with Superset's specific database models, task contexts, and REST API decorators, facilitating a more modular architecture for extensions and future refactoring.
superset/core/api · high confidence
Dashboard module restructured into dedicated Python package
The dashboard functionality has been reorganized from a monolithic structure into a dedicated \superset/dashboards\ package. This change introduces a new \api.py\ module that centralizes all dashboard REST endpoints, command integrations, and schema definitions, alongside new utility modules for handling dashboard layout repair (\layout.py\), filter scope derivation (\filter\_scope.py\), and access filtering (\filters.py\). For users, this represents an internal architectural cleanup that improves code maintainability and separation of concerns without altering the external dashboard API contract or user-facing features.
superset/dashboards · high confidence
Dashboard operations are now handled by dedicated command classes
The dashboard command logic has been reorganized into a dedicated \superset/commands/dashboard\ package, introducing specific command classes for create, update, delete, copy, export, import, favorite/unfavorite, soft-delete, and version restore. This change ensures that all dashboard lifecycle operations are executed through a unified, transactional command pattern, improving consistency and error handling across the platform.
superset/commands/dashboard · high confidence
Dataset commands are reorganized into a dedicated module
The dataset command logic (create, update, delete, duplicate, export, refresh, restore, and cache warming) has been moved into a new \superset/commands/dataset/\ package. This change consolidates the implementation details for dataset operations, improving code organization and maintainability without altering the external API or user-facing behavior.
superset/commands/dataset · high confidence
Introduction of the connectors package namespace
The \superset/connectors\ directory is now a formal Python package, marked by the addition of an \\_\init\\_.py\ file containing the standard Apache License 2.0 header. This establishes the namespace for connector-related modules, laying the structural groundwork for the refactoring of Druid and SQL Alchemy sources into a unified connector interface.
superset/connectors · high confidence
Migrate SQL Lab persistence views to a modular package structure
The SQL Lab persistence logic has been reorganized from a monolithic view file into a dedicated \superset/views/sql\_lab\ package. This change introduces \schemas.py\ to define the \SqlJsonPayloadSchema\ for validating SQL Lab API inputs (including \tmp\_table\_name\ validation) and \views.py\ to host the \SavedQueryView\ and \TabStateView\. The \TabStateView\ implementation enforces strict ownership checks on tab state updates and deletions, ensuring users can only modify their own tabs, and restricts the fields updatable via the PUT endpoint to a specific whitelist (\\_TAB\_STATE\_PUT\_FIELDS\) to prevent unauthorized state changes.
_superset/views/sql\lab · high confidence
Relocate core Superset models into the superset.models package
The application's data models (including Database, Dashboard, Slice, Query, and related entities) have been moved from their previous locations into the new superset.models package. This reorganization consolidates the ORM definitions under a single namespace, improving code structure and maintainability without changing the underlying database schema or user-facing functionality.
superset/models · high confidence
Reorganized report and alert commands into a dedicated module
The report and alert command logic has been reorganized into a new \superset/commands/report\ package. This change introduces a structured set of command classes—including \AlertCommand\, \BaseReportScheduleCommand\, \CreateReportScheduleCommand\, \DeleteReportScheduleCommand\, \ExecuteReportScheduleNowCommand\, and \ChartDataRequestError\—to handle alert validation, report scheduling, execution, and data fetching. This modularization improves code maintainability and separates concerns for alert queries, report creation/deletion, and execution workflows.
superset/commands/report · high confidence
Superset CLI is restructured into modular command files
The \superset/cli\ package has been split from a single monolithic file into multiple dedicated modules (e.g., \deletion\_retention.py\, \examples.py\, \export\_example.py\, \guest\_token.py\, \importexport.py\, \mcp.py\, \reset.py\, \sync\_subjects.py\, \test.py\, \test\_db.py\, \thumbnails.py\, \update.py\). This refactoring organizes CLI commands by feature area, making the command-line interface easier to maintain and extend. The main entry point (\main.py\) now dynamically discovers and registers these commands using \pkgutil\, ensuring all new subcommands are automatically available without manual registration in a central file.
superset/cli · high confidence
Behavioural changes
Added missing \_\_init\_\_.py for embedded\_dashboard module
The superset/embedded\dashboard directory now includes an \\init\\_.py file, ensuring the directory is recognized as a Python package. This change resolves potential import issues for the embedded dashboard functionality by properly initializing the module namespace.
_superset/embedded\dashboard · medium confidence
Alert and Report Modal UI and behavior overhaul
The Alert and Report creation/editing modal has been completely rewritten in TypeScript with a redesigned user interface. Key changes include a new scheduling experience that lets users choose between a visual picker and a raw CRON expression input, and a corrected status indicator that no longer displays a misleading green success icon for reports that have never run. The notification configuration now supports CC and BCC email fields, user lookup for recipients, and paginated Slack channel selection. Additionally, the modal now uses the SubjectPicker for owners/editors and integrates the extensions registry for date filtering.
superset-frontend/src/features/alerts · high confidence
Annotation layer and CSS template commands now enforce database transactions
The command implementations for annotation layers and CSS templates have been updated to wrap their database operations in a transaction decorator. This ensures that create, update, and delete actions for these resources are atomic: if any part of the operation fails, the entire change is rolled back, preventing partial updates or data inconsistencies in the annotation layers and CSS templates.
_superset/commands/annotation\layer, superset/commands/css · high confidence
Backfilled Simplified Chinese translations for missing UI strings
The Simplified Chinese (zh) translation catalog has been significantly expanded with machine-translated content for previously untranslated strings, particularly in chart configuration help text (e.g., histogram cumulative/normalize options) and error messages. This ensures that users interacting with the application in Chinese now see localized labels and explanations for features that were previously displayed in English, improving the overall localization coverage and consistency of the interface.
superset/translations/zh · high confidence
Centralized caching utilities and configurable hash algorithms
The \superset/utils\ package now provides a unified set of caching utilities, including \cache.py\ for key generation and value persistence, \cache\_manager.py\ for managing distinct cache instances (data, thumbnails, filter state), and \cache\_keys.py\ for handling per-user impersonation keys. A key behavioral change is the introduction of a configurable hash algorithm (defaulting to SHA-256 via \SupersetCache\) to replace the previous MD5 default, ensuring compatibility with FIPS-mode environments and allowing administrators to tune hash performance. Additionally, the \csv.py\ module now includes logic to detect and escape values that resemble spreadsheet formulas (e.g., starting with \=\, \+\, \-\) to prevent data injection issues during CSV exports.
superset/utils · high confidence
Chart card navigation and soft-delete behavior improvements
The ChartCard component now prevents duplicate browser history entries when clicking a chart thumbnail, ensuring the Back button returns users to the previous page as expected. Additionally, when the SoftDelete feature flag is enabled, deleting a chart via the card menu triggers an archive dialog instead of a permanent deletion, removing the previous friction of typing 'DELETE' to confirm.
superset-frontend/src/features/charts · high confidence
Chart import now supports restoring soft-deleted charts and filtering annotations
The chart import command has been updated to handle soft-deleted charts: re-importing a chart with a matching UUID now implicitly restores the deleted chart (clearing its deletion timestamp) and updates its configuration, provided the user has write and editor permissions. Additionally, the import process now filters chart annotations to retain only FORMULA types, ignoring other annotation layers during the import. The import logic also resolves dataset and database dependencies in the correct order and applies default viewer permissions based on the current user's groups.
superset/commands/chart/importers/v1 · high confidence
Database management operations are now handled by dedicated command classes
The \superset/commands/database\ module has been reorganized to use explicit command classes for core database lifecycle operations. Creating, updating, deleting, and testing database connections now go through \CreateDatabaseCommand\, \UpdateDatabaseCommand\, \DeleteDatabaseCommand\, and \TestConnectionDatabaseCommand\ respectively. This change introduces stricter validation, such as preventing unsafe credential reuse when connection destinations change, and ensures that database deletion is blocked if associated datasets (including soft-deleted ones) or reports still exist. It also centralizes OAuth2 token storage and SSH tunnel exception handling within this command layer.
superset/commands/database · high confidence
Database schema initialization and evolution via Alembic migrations
The \superset/migrations/versions\ directory contains the Alembic migration scripts that define the application's database schema history. These files manage the creation of core tables (such as \dashboards\, \slices\, \datasources\, and \tables\), the addition of new columns (like \slug\, \json\_metadata\, and \cache\_timeout\), and the enforcement of constraints and foreign keys. This location serves as the historical record of schema changes, ensuring that the database structure is correctly initialized and upgraded across different versions of the software.
superset/migrations/versions · high confidence
Deck.gl charts now support dual MapLibre/Mapbox rendering with improved categorical color consistency
The deck.gl visualization plugin now renders maps using either MapLibre or Mapbox, allowing users to choose their preferred map provider while preserving OpenStreetMap styles and fixing issues with missing Mapbox API keys. For categorical charts like scatter plots, the legend swatches and point colors now resolve from the same slice ID, ensuring they match exactly. The multi-layer (deck\_multi) chart has been modernized to fetch sub-layers client-side, fixing autozoom behavior and datasource resolution for saved charts.
superset-frontend/plugins/preset-chart-deckgl · high confidence
Helm chart templates restructured with new component deployments and helper logic
The Helm chart templates in this location have been reorganized to support a modular architecture. New deployment templates have been added for the Celery Beat scheduler, Flower monitoring, MCP server, and WebSocket components, each with their own configuration scopes (e.g., \supersetCeleryBeat\, \supersetWebsockets\). The \\helpers.tpl\ file now includes comprehensive helper functions for standardized Kubernetes labels, service account resolution, and a new coalescing resolver system that supports both new top-level \database.\\/\cache.\\ values and legacy \supersetNode.connections.\\ keys to ensure a smooth migration path. Additionally, a \NOTES.txt\ template has been introduced to provide users with dynamic, context-aware instructions for accessing the application based on their service type (NodePort, LoadBalancer, etc.), and a \configmap-superset.yaml\ template allows for the injection of extra configuration files via the \extraConfigs\ value.
helm/superset/templates · high confidence
Introduce dashboard RBAC, embedded views, and subject-based asset creation
The dashboard views now enforce stricter access controls by requiring editorship for deletion and applying a DashboardAccessFilter to list views. New dashboards created via the UI are automatically scoped to the creator's groups using the Subject model, and a configurable post-creation hook (AFTER\_ASSET\_CREATE) allows for custom logic upon asset creation. Additionally, a new embedded dashboard view is available behind the EMBEDDED\_SUPERSET feature flag, which serves server-side rendered dashboards to anonymous users, and the dashboard list view now supports multi-export functionality.
superset/views/dashboard · high confidence
Introduce dedicated command layer for dashboard native filter state management
This change introduces a new set of backend commands (Create, Get, Update, Delete) within the \superset/commands/dashboard/filter\_state\ package to handle the lifecycle of native filter state. These commands manage the storage and retrieval of filter configurations in the temporary cache, ensuring that access is validated against the dashboard's permissions. A key behavioral addition is the \GetFilterStateCommand\, which now cross-references cached filter IDs against the dashboard's native filter configuration metadata to return a map of filter IDs to their human-readable names, addressing the previous limitation where cached state lacked label information.
_superset/commands/dashboard/filter\state · high confidence
Introduce new database view and validation logic
This change introduces a new modular structure for database views, splitting the previous monolithic implementation into separate files for views and validators. It adds a \DatabaseView\ class that exposes a list endpoint for databases, and a \sqlalchemy\_uri\_validator\ function that ensures database connection strings are valid before use. Additionally, it includes a \schema\_allows\_file\_upload\ helper that checks if a specific schema is permitted for file uploads, handling case-sensitivity nuances for engines like PostgreSQL.
superset/views/database · high confidence
Introduce structured command pattern for temporary explore form data operations
This change refactors the handling of temporary explore form data by introducing a dedicated command structure in the \superset/commands/explore/form\_data\ module. It adds specific command classes (\CreateFormDataCommand\, \GetFormDataCommand\, \UpdateFormDataCommand\, \DeleteFormDataCommand\) along with supporting parameter and state definitions. This provides a standardized, validated, and access-controlled interface for managing temporary chart configurations in the cache, replacing previous ad-hoc logic with a consistent command pattern.
_superset/commands/explore/form\data · high confidence
Introduces asset bundle macros for prefixed URL support
A new \asset\_bundle.html\ partial has been added to the templates directory, defining \js\_bundle\ and \css\_bundle\ macros. These macros iterate over JavaScript and CSS manifests to generate script and link tags, incorporating an \assets\_prefix\ parameter. This change enables the application to correctly resolve static assets when deployed under a prefixed URL path, supporting the new deployment configuration.
superset/templates/superset/partials · high confidence
Log view and API now respect SUPERSET\_LOG\_VIEW configuration
The Log model view and its associated REST API endpoints are now gated by the SUPERSET\_LOG\_VIEW configuration flag (in addition to the existing FAB\_ADD\_SECURITY\_VIEWS check). When SUPERSET\_LOG\_VIEW is disabled, the Log view is hidden from the UI and the API endpoints return 404 errors, allowing administrators to completely disable log visibility without removing the underlying model or permissions.
superset/views/log · high confidence
MCP service introduces non-blocking runtime validation for chart configurations
The MCP service now includes a runtime validation layer that checks chart configurations for potential usability issues—such as high cardinality, inappropriate chart types, and format mismatches (e.g., currency on counts)—but returns these findings as informational warnings rather than blocking errors. This ensures that chart generation proceeds even when suboptimal settings are detected, while still providing users with suggestions to improve their visualizations.
_superset/mcp\service/chart/validation/runtime · high confidence
Migrate Chord, Horizon, and Paired T-Test chart plugins to the new frontend pipeline
The Chord, Horizon, and Paired T-Test chart plugins have been rewritten to use the modern \SuperChart\ component and the new \buildQuery\/\transformProps\ architecture, replacing the legacy \explore\_json\ and \viz.py\ backend pipeline. This change updates the frontend implementation for these specific visualizations to align with the current Superset plugin standards, ensuring they load dynamically and process data through the standardized query and property transformation layers.
superset-frontend/plugins/plugin-chart-chord, superset-frontend/plugins/plugin-chart-horizon, superset-frontend/plugins/plugin-chart-paired-t-test · high confidence
Modernize example data loading with Parquet and YAML configs
The example data loading system has been refactored to use Parquet files and YAML configuration files instead of the previous hardcoded Python scripts. This change introduces a new auto-discovery mechanism in \data\_loading.py\ that scans for \dataset.yaml\ and \data.parquet\ files, allowing for more flexible and maintainable example datasets. Existing examples like \birth\_names\ and \countries\ are now defined via these new config structures, and the \deckgl\_demo\ dashboard and its associated chart and dataset YAMLs are included as part of this modernized structure.
superset/examples · high confidence
New DAO layer with unified filtering and LIKE-safety
The \superset/daos\ package introduces a new data-access layer built around a generic \BaseDAO\ and a \ColumnOperator\ filtering system. This change standardizes how entities (charts, dashboards, datasets, databases, etc.) are queried by enforcing SQL-faithful NULL handling and escaping wildcards in LIKE-family operators to prevent injection. It also adds specialized filtering capabilities for each entity, such as filtering charts and dashboards by editor or favorite status, and allows datasets to be filtered by database name.
superset/daos · high confidence
New React-based chart management views
The chart management interface has been migrated to a new React-based implementation. This change introduces new view files (\views.py\, \filters.py\) that serve the \/chart/add\ and \/chart/list/\ routes, replacing the previous legacy CRUD views. Users will now interact with the chart creation and listing pages through the updated React frontend, which is consistent with the broader shift to React-based data management interfaces in Superset.
superset/views/chart · high confidence
New command structure for chart data retrieval and streaming CSV exports
The chart data layer now uses dedicated command classes to handle data fetching and export. A new \ChartDataCommand\ manages data retrieval, including logic to surface validation errors in the View Query modal when appropriate, while a new \StreamingCSVExportCommand\ enables streaming CSV exports of chart data without row limits, leveraging the underlying streaming export framework.
superset/commands/chart/data · high confidence
New command-based architecture for saved query operations
The \superset/commands/query\ module has been introduced to handle saved query lifecycle operations using a dedicated command pattern. This change adds specific commands for deleting (\DeleteSavedQueryCommand\) and exporting (\ExportSavedQueriesCommand\) saved queries, along with associated exception classes (\SavedQueryDeleteFailedError\, \SavedQueryNotFoundError\, etc.) and a Data Access Object (\SavedQueryDAO\) integration. The export command now generates YAML files that include database metadata, ensuring that exported saved queries retain necessary context for re-importing or sharing.
superset/commands/query · high confidence
New commands for deleting dataset columns and metrics
This change introduces dedicated command classes for deleting dataset columns and metrics, replacing or supplementing previous ad-hoc deletion logic. The new \DeleteDatasetColumnCommand\ and \DeleteDatasetMetricCommand\ enforce editorship permissions via the security manager, validate that the target column or metric exists, and wrap the deletion in a transaction that raises specific, user-friendly exceptions (not found, forbidden, or delete failed) on error. This provides a consistent, secure, and auditable path for removing these dataset components.
superset/commands/dataset/columns, superset/commands/dataset/metrics · high confidence
New datasource views module with access-controlled samples and metadata endpoints
A new \superset/views/datasource\ package has been introduced, replacing legacy view logic with a structured module containing schemas, utilities, and Flask views. This change introduces explicit access control enforcement for the \get\_samples\ and \external\_metadata\ endpoints, ensuring users can only retrieve sample data or metadata for datasets they are authorized to access. The samples endpoint now supports pagination and filtering via new request schemas, and the module provides a centralized location for datasource-related API logic, including dataset saving and metadata retrieval.
superset/views/datasource · high confidence
New import error handling infrastructure
The import command module now includes specific exception classes for handling invalid import scenarios. Users will see distinct error messages for issues such as incorrect file versions, missing valid files, or unsupported file formats during the import process.
superset/commands/importers · high confidence
New modular chart data API and dashboard filter context
The chart data retrieval logic has been reorganized into a dedicated \superset/charts/data\ module, introducing the \ChartDataRestApi\ class to handle chart data requests. This change includes a new \dashboard\_filter\_context\ component that correctly applies dashboard filter defaults to charts based on their layout scope, replacing the previous reliance on potentially stale \chartsInScope\ caches. Additionally, a \form\_data\ utility now exposes request fields to Jinja template macros via the Flask \g\ object, ensuring consistent data access for chart rendering.
superset/charts/data · high confidence
New versioned import command dispatchers for charts and databases
The import logic for charts and databases has been restructured to use new dispatcher commands (\ImportChartsCommand\ and \ImportDatabasesCommand\) located in \superset/commands/chart/importers\ and \superset/commands/database/importers\. These dispatchers iterate through a list of versioned command implementations (currently only v1) to handle import files, allowing for future backward-compatible versioning of the import process. This change organizes the command structure according to SIP-92, moving the import orchestration into dedicated modules that validate and route import contents to the appropriate handler.
superset/commands/chart/importers, superset/commands/database/importers · high confidence
Parallel Coordinates chart plugin reimplementation
The Parallel Coordinates chart plugin has been rewritten from the legacy \viz.py\ pipeline to a modern React-based implementation. This change introduces a new \buildQuery\ function that ensures the sort metric is correctly included in the query results and respects the \order\_desc\ flag, while ignoring residual ordering fields from other visualization types. The \transformProps\ logic has been updated to safely handle undefined metrics, preventing frontend crashes when navigating quickly between pages. Additionally, the chart now supports a new 'Data Table' toggle in the control panel to display an interactive grid alongside the visualization, and styling has been updated to respect the application's dark mode theme.
superset-frontend/plugins/plugin-chart-parallel-coordinates · high confidence
Partition chart migrated to new plugin architecture with data normalization fix
The Partition chart plugin has been rewritten to use the modern Superset plugin architecture, replacing the legacy explore\_json and viz.py pipeline. This migration includes a new React-based wrapper, standardized control panel configuration, and updated query building logic. Additionally, a bug fix ensures that ancestor-path array names in the data hierarchy are normalized to leaf values, preventing display issues in the chart visualization.
superset-frontend/plugins/plugin-chart-partition · high confidence
Pivot Table plugin restructured and migrated to modern React patterns
The Pivot Table plugin has been reorganized into a new file structure and migrated from class-based components to modern React function components. This update includes the addition of a CHANGELOG.md to track version history, improved TypeScript typing, and the integration of Ant Design icons for the expand/collapse controls. The plugin now supports dynamic currency formatting with auto-detection, allows HTML rendering in cells, and implements correct non-additive totals and subtotals via database rollup queries. Additionally, it features a new context menu for drill-to-detail and drill-by actions, cross-filtering support, and enhanced conditional formatting controls.
superset-frontend/plugins/plugin-chart-pivot-table · high confidence
Refactor dashboard permalink commands to use DAOs and support hash algorithm fallbacks
The dashboard permalink logic has been restructured into dedicated command classes (Create, Get, Base) within the superset/commands/dashboard/permalink module. This change introduces support for configurable hash algorithms, allowing the system to check fallback algorithms for backward compatibility when retrieving existing permalinks. Additionally, the implementation now uses the Data Access Object (DAO) pattern for database interactions and ensures data consistency by using database flush operations instead of commits during permalink creation.
superset/commands/dashboard/permalink · high confidence
Refactor explore permalink commands to use DAO and handle template errors
The permalink command implementation in superset/commands/explore/permalink has been restructured to use the KeyValueDAO for data persistence instead of direct session commits, and now explicitly catches Jinja2 TemplateError during access validation to raise a user-friendly SupersetTemplateException. This change improves error handling for permalinked query datasources and aligns the command with the DAO pattern.
superset/commands/explore/permalink · high confidence
Refactored database connection form into modular, validated components
The database connection form in the Database Modal has been restructured into a modular, component-based architecture. This change introduces dedicated form fields for common parameters (host, port, database, schema), OAuth2 client information, and encrypted credentials, along with a new TableCatalog component for Google Sheets. The refactoring ensures consistent validation, proper handling of public/private Google Sheets access, and improved maintainability of the connection form logic.
superset-frontend/src/features/databases · high confidence
Reports and alerts notifications are refactored into a modular plugin architecture
The notification delivery system for reports and alerts has been restructured into a dedicated \superset/reports/notifications\ package with a plugin-based design. This change introduces distinct, extensible classes for Email, Slack (including the new Slack V2 API with file upload support), and Webhook notifications, replacing the previous monolithic implementation. Users benefit from improved reliability through configurable retry logic with backoff, better security via strict SSRF validation for webhook targets, and enhanced features such as Slack V2 file uploads, configurable email subject date formats, and granular error handling that distinguishes between transient and permanent delivery failures.
superset/reports/notifications · high confidence
Reports feature reorganized into a new modular structure with expanded configuration options
The ReportModal feature has been reorganized into a new modular structure, introducing a HeaderReportDropdown for managing report states and a dedicated reducer for handling report lifecycle actions (create, edit, delete, fetch). This change adds support for XLSX (Excel) attachments in email reports, optional CC and BCC email fields, and retry-on-failure configuration options. The modal now correctly handles chart reports within a dashboard context by sending only the chart ID to avoid API errors, and enforces server-side recipient handling for subscriptions.
superset-frontend/src/features/reports · high confidence
Restore legacy /superset URL redirects to prevent 404s for bookmarks and deep links
A new WSGI middleware layer has been added to handle backward compatibility for URLs that still include the historical \/superset\ prefix. This middleware intercepts requests to legacy paths (such as \/superset/dashboard/\, \/superset/explore/\, and \/superset/sql/\<db\_id\>/\) and issues 308 Permanent Redirects to their modern equivalents (e.g., \/dashboard/\, \/explore/\, \/sqllab/?dbid=\<id\>\). This ensures that existing bookmarks, email links, and external integrations continue to work without breaking, specifically addressing regressions where the removal of the prefix caused 404 errors for deep links and the app root.
superset/middleware · high confidence
Restructure Explore command logic and fix SQL Lab author access
The Explore command logic has been reorganized into a dedicated module (\superset/commands/explore\), introducing a \GetExploreCommand\ that handles retrieving form data from permalinks or cache and resolving datasource information. This change also fixes a security/behavioral issue where SQL Lab query authors were previously blocked from accessing the Explore view for their own queries; the new code explicitly grants an access bypass for query authors, ensuring they can seamlessly transition from SQL Lab to Explore.
superset/commands/explore · high confidence
Restructured dashboard import command hierarchy with legacy v0 support
The dashboard import logic has been reorganized into a dedicated \superset/commands/dashboard/importers\ package. A new dispatcher (\dispatcher.py\) routes import requests to versioned command classes, currently supporting the v1 importer while explicitly excluding the legacy v0 importer from the HTTP API to prevent unsafe overrides. The legacy v0 importer (\v0.py\) is retained as a separate module for use via the \legacy\_import\_dashboards\ CLI command, preserving backward compatibility for older export formats while tightening control over API-based imports.
superset/commands/dashboard/importers · high confidence
Restructured dataset importers with new v1 dispatcher and legacy v0 isolation
The dataset import logic has been reorganized into a new package structure under \superset/commands/dataset/importers\. A new dispatcher (\dispatcher.py\) now handles imports via the HTTP API, explicitly routing only to the new v1 command and deliberately excluding the legacy v0 importer to prevent unowned dataset overrides. The legacy v0 importer code has been moved to its own file (\v0.py\) and is no longer part of the standard dispatch chain, remaining accessible only via the specific \legacy\_import\_datasources\ CLI command. This change isolates the legacy behavior and enforces stricter ownership checks for API-based imports.
superset/commands/dataset/importers · high confidence
SQL Lab query cancellation now correctly marks queries as stopped
When a user cancels a query in SQL Lab, the system now explicitly marks the query as 'stopped' rather than leaving it in a 'stuck running' state. This ensures that the query history accurately reflects the cancellation and prevents the query from blocking subsequent operations or appearing erroneously as active.
superset · high confidence
SQLAlchemy connector models and utilities are restructured and re-implemented
The SQLA connector package has been refactored to align with the new superset-core architecture. The \models.py\ file now imports the base \Dataset\ model from \superset\_core.common.models\ and integrates with the new \Explorable\ protocol and \Subject\ model infrastructure. The \utils.py\ module has been rewritten to handle virtual dataset metadata extraction with improved Jinja template processing, specifically softening \UndefinedError\ exceptions during metadata refresh to prevent chart cache invalidation issues when runtime context is missing. Additionally, the connector now supports catalog-aware queries and enforces stricter security checks on virtual dataset SQL (allowing only single SELECT statements).
superset/connectors/sqla · high confidence
Secure database import with credential validation and permission syncing
The database import command now enforces stricter security and reliability during the import process. It prevents overwriting an existing database connection with a different endpoint (host/port or engine parameters) unless fresh credentials are explicitly provided, blocking the silent reuse of stored passwords or SSH tunnel keys. Additionally, it gracefully handles errors when syncing catalog and schema permissions, ensuring that transient database connectivity issues do not fail the entire import operation.
superset/commands/database/importers/v1 · high confidence
Separate database initialization scripts for Cypress and examples environments
The Docker entrypoint initialization logic has been split into two distinct scripts: \cypress-init.sh\ and \examples-init.sh\. The new \cypress-init.sh\ script exclusively creates the \superset\_cypress\ database, isolating the test environment from the main examples data. The \examples-init.sh\ script handles the creation of the examples database, user, and associated permissions. This separation ensures that the database setup for Cypress end-to-end tests no longer interferes with or depends on the examples database schema and data.
docker/docker-entrypoint-initdb.d · high confidence
Serve language packs as versioned, immutable-cacheable scripts
The translation system now serves compiled language packs as JSON files with content-addressed URLs (based on SHA-256 hashes), enabling browsers to cache them as immutable assets. This change introduces a new \utils.py\ module to manage pack loading and versioning, an \empty\_language\_pack.json\ for the default English locale, and a \do-not-translate.txt\ registry to prevent machine-consumed strings (like SQL keywords or enum values) from being translated. These updates ensure that language packs are efficiently cached and that critical internal strings remain consistent across all locales.
superset/translations · high confidence
Stabilize thumbnail cache digests with sorted datasources and user-specific hashing
The thumbnail digest generation logic has been updated to ensure consistent cache keys. Datasources and charts are now sorted by ID before being included in the digest string, preventing cache collisions caused by non-deterministic ordering. Additionally, the digest now incorporates the executor identity (user ID) and row-level security (RLS) filters, ensuring that thumbnails are correctly scoped to specific users and their data access permissions.
superset/thumbnails · high confidence
Standardized datasource access checks for Row-Level Security rule management
The RLS rule commands (create, update, and delete) now enforce standard datasource access permissions before allowing any modifications. Users can only create, update, or delete Row-Level Security rules if they have access to every datasource referenced by those rules. This change prevents unauthorized users from accessing rule details (such as rule names) or modifying rules tied to datasources they cannot view, ensuring consistent security enforcement across all RLS operations.
superset/commands/security · high confidence
Superset Helm chart deprecated with structured configuration schema
The Superset Helm chart (version 0.22.8, app version 6.1.0) is now officially deprecated in favor of the Apache Superset Kubernetes Operator. This release introduces a breaking change to workload labels, switching from legacy \app\/\release\ labels to Kubernetes recommended \app.kubernetes.io/\*\ labels, which requires deleting existing workloads before upgrading. It also replaces the flat \supersetNode.connections\ configuration with structured \database\ and \cache\ sections, deprecates the \init.initscript\ customization in favor of the built-in init template, and adds a \values.schema.json\ for early validation of configuration values.
helm/superset · high confidence
Superset plugin generator scaffolded with modernized build and test configuration
The \generator-superset\ Yeoman generator now produces new visualization plugins with an updated project structure and tooling. Generated plugins include a Jest configuration that explicitly sets the test environment to \jsdom\ and maps static assets (images, fonts) to string mocks, resolving previous build failures. The generated \package.json\ templates specify React 17 as a peer dependency and include scripts for both CommonJS and ESM output. Additionally, the generator's own source code has been migrated to ES modules, and it now imports string transformation utilities from \lodash-es\ instead of the full \lodash\ library to reduce bundle size.
superset-frontend/packages/generator-superset · high confidence
Unified dataset and semantic view listing with RLS visibility
The combined datasource list endpoint now returns a paginated, unified view of both traditional datasets and semantic views. This change ensures that Row-Level Security (RLS) filter summaries are correctly injected into the response for dataset entries, allowing users to see RLS indicators in the combined list just as they do in the standalone dataset list. The filtering logic also correctly handles schema filters when querying semantic layer connections, preventing mismatched results.
superset/commands/datasource · high confidence
Unified file upload command with dedicated readers for CSV, Excel, and Columnar formats
The file upload logic in the database commands has been refactored into a new \superset/commands/database/uploaders\ package. This change introduces a unified \UploadCommand\ that delegates file parsing to specific reader classes: \CSVReader\ (with improved encoding detection and error reporting), \ExcelReader\, and \ColumnarReader\ (supporting Parquet files and ZIP archives). This structure replaces the previous monolithic upload implementation, allowing for better separation of concerns and more robust handling of different file types during dataset creation.
superset/commands/database/uploaders · high confidence
Updated German translations for UI strings and help text
The German (de) translation file has been refreshed with new and corrected translations for various interface elements, including dashboard and chart labels, error messages, and help text for histogram options (cumulative and normalize). This ensures that German-speaking users see accurate and consistent terminology across the application.
superset/translations/de · high confidence
Updated Russian language translations
The Russian (ru) translation catalog has been updated with new and revised translations for various interface strings, including histogram options, dashboard filters, and system messages. This ensures that Russian-speaking users see accurate and consistent terminology across the application.
superset/translations/ru · high confidence
Upgrade to SQLAlchemy 2.0
The application has been upgraded to SQLAlchemy 2.0, which requires updates to the ORM syntax (such as \select()\ and \case()\) and session management. This change improves performance and aligns with modern Python database standards, but may require adjustments to custom extensions or scripts that interact directly with the database layer.
(repo-wide) · high confidence
User creation and editing now display specific validation and error messages
The UserListModal and its supporting utilities have been updated to provide clearer feedback during user management. When creating or editing a user, the system now explicitly displays password validation errors (such as minimum length requirements) returned by the backend, rather than failing silently or showing generic messages. Additionally, duplicate username and email attempts now trigger specific, user-friendly error notifications (e.g., "This username is already taken") instead of raw database constraint errors. These changes are implemented in the new \UserListModal.tsx\, \utils.ts\, and \utils.test.ts\ files within the users feature directory.
superset-frontend/src/features/users · high confidence
Version history panel layout and preview behavior for charts and dashboards
The version history panel now stays within the viewport on narrow screens by switching to an absolute overlay below the XL breakpoint, and the preview experience has been refined to render the starting version as the oldest history row, suppress automatic chart normalization changes, and correctly carry affected chart names in the rollup impact payload. Additionally, the panel design fidelity has been improved, history actions are cleaned up and refreshed after saves, and the system now uses typed app dispatch for better state management.
superset-frontend/src/features/versionHistory · medium confidence
Word Cloud plugin rewritten with encoding-based API and new controls
The Word Cloud plugin has been completely rewritten to use a declarative encoding configuration (mapping data fields to text, font size, color, and font weight) instead of the previous hardcoded logic, and the control panel now uses dedicated React components for rotation and color scheme selection. This change improves color consistency across refreshes, fixes series label formatting for custom SQL queries, and resolves word cloud randomness issues, while also introducing performance optimizations to reduce rendering overhead.
superset-frontend/plugins/plugin-chart-word-cloud · high confidence
Fixes
Baseline version capture for pre-existing datasets and dashboards
A new baseline capture system ensures that datasets and dashboards created before versioning was enabled now have a complete version history. The system automatically inserts a synthetic "version 0" baseline row for these entities during their next save, capturing their current state. This fix resolves the issue where editing columns or metrics on pre-existing entities resulted in an empty version history dropdown, and ensures that restore operations can correctly revert to the initial state of these entities.
superset/versioning/baseline · high confidence
Country Map plugin reimplementation with conditional formatting and security fixes
The Country Map plugin has been rewritten in TypeScript, introducing support for custom conditional color formatting on numeric metrics and adding an HTML-escaping function to prevent XSS attacks. The update also corrects several geographic data issues, including unique ISO codes for Madagascar and Alborz, the addition of the Karonga district in Malawi, and boundary corrections for Karelia.
superset-frontend/plugins/plugin-chart-country-map · high confidence
Fix broken navigation links in the All Entities table when deployed under a URL prefix
The AllEntitiesTable component now correctly handles router-relative URLs returned by the backend by wrapping them with the application root prefix. This ensures that clicking on entity links (Dashboards, Charts, Queries) in the tag management view navigates to the correct destination, preventing broken links when Superset is deployed under a sub-path.
superset-frontend/src/features/allEntities · high confidence
Fix duplicate navigation history entries on dashboard card clicks
The DashboardCard component now ensures that clicking a dashboard card navigates to the dashboard URL exactly once. Previously, because both the card container and an internal link were clickable, a single click could trigger two identical history entries, causing the browser's Back button to return the user to the list view instead of the previous page. This change corrects that behavior so navigation works as expected.
superset-frontend/src/features/dashboards · high confidence
Initialize static upload directories in version control
Added .gitkeep placeholder files to the superset/static and superset/static/uploads directories to ensure these folders are tracked by Git. This change ensures that the directory structure for static assets and uploads is preserved in the repository, preventing issues where empty directories might be ignored by version control systems.
superset/static · high confidence
Refactored Docker entrypoints for better process management and configuration
The Docker entrypoint scripts have been restructured to improve reliability and observability. The main server entrypoint now uses \exec\ to run Gunicorn, ensuring it correctly receives termination signals (SIGTERM) for graceful shutdowns. Additionally, Gunicorn is now configured to support StatsD metrics collection via environment variables (SERVER\_STATSD\_HOST, SERVER\_STATSD\_PORT), allowing users to enable monitoring without code changes. A new CI-specific entrypoint was added to handle initialization and thread configuration, and the WebSocket server entrypoint was updated to run from a writable directory to support file logging for unprivileged users.
docker/entrypoints · high confidence
SQL Lab commands reorganized into a dedicated module with tightened security and reliability fixes
The SQL Lab command logic has been reorganized into a new \superset/commands/sql\_lab\ package (containing \estimate.py\, \execute.py\, \export.py\, \query.py\, \results.py\, and \streaming\_export\_command.py\). This refactor introduces stricter security by re-validating access against the rendered SQL before execution and applying SQL controls (RLS, DML, and disallowed functions/tables) to cost estimation. It also improves reliability by releasing database connections before fetching results from the backend, wrapping raw DBAPI and Jinja errors to prevent 500 leaks, and fixing Decimal TypeErrors in the results handler.
_superset/commands/sql\lab · high confidence
Structured validation pipeline for MCP chart generation
The MCP service now enforces a multi-layered validation process for chart generation requests before execution. This change introduces a dedicated validation module that checks request structure, validates chart types against the plugin registry, and verifies that referenced columns exist in the target dataset. Users will receive specific, actionable error messages for issues like missing fields, invalid chart types, or ambiguous column references, rather than generic failures. Runtime warnings are surfaced as informational metadata instead of blocking errors, improving the robustness of chart creation via the MCP interface.
_superset/mcp\service/chart/validation · high confidence
Support URL prefix for OpenAPI and Swagger UI
The OpenAPI specification and Swagger UI now correctly handle deployments behind a URL prefix (reverse proxy) by respecting the \\APPLICATION\_ROOT\\ configuration. This ensures that API links and resources resolve to the correct paths when Superset is accessed via a sub-path, fixing issues where URLs were previously malformed or broken in proxied environments.
superset/openapi · high confidence
Test coverage
Added Helm chart unit tests for Superset deployment templates; Added integration tests for the Chart Data API; Added unit tests for chart data query validation and export sanitization; Added unit tests for chart data retrieval and import migration commands; Expanded test coverage for SQL Lab, security, and MCP tools; Home page components migrated to React Testing Library; New test runner script for faster, targeted test execution.
Dependencies
Migration to uv-based dependency management with security-hardened base requirements
The project has replaced its previous dependency resolution tooling with \uv\ (via \uv-pip-compile.sh\), introducing a new \requirements/\ directory structure that uses \.in\ source files and \pyproject.toml\ to generate pinned \.txt\ requirements. This change enforces stricter security postures by pinning minimum versions for critical libraries to address specific vulnerabilities: \urllib3\ ([CVE redacted]), \werkzeug\ ([CVE redacted]), \cryptography\ ([CVE redacted]), \pyarrow\ ([CVE redacted]), \pyopenssl\ ([CVE redacted]), and \requests\ ([CVE redacted]). Additionally, the build process now explicitly pins \setuptools\ below version 85 to prevent breakage from the removal of \pkg\_resources\, and explicitly declares \cachetools\ to resolve a transitive dependency drop in \google-auth\ \>= 2.53.0.
requirements · high confidence
Routine dependency updates across the project
This change updates dependencies across 44 manifests in the project, including bumping packages such as @types/node, globals, typescript-eslint, acorn, webpack, and dompurify to their latest versions. These updates are routine maintenance and do not introduce new user-facing features or behavioral changes.
(dependencies) · high confidence
Housekeeping
Initial changelog for ECharts plugin
The \superset-frontend/plugins/plugin-chart-echarts\ package now includes a \CHANGELOG.md\ file documenting its history, starting with version 0.20.0 (released 2024-09-09). This entry point establishes the change log for the ECharts visualization plugin, covering the bug fixes and features introduced in that release.
superset-frontend/plugins/plugin-chart-echarts · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 50.
Lenses
- Code Health 74
- Architecture 62
- Maturity 74
- Readiness 46
- Security 53
- Accessibility 48
Changes since last survey
- 300 commits — 139 feature/other, 161 fixes
By area
- superset-frontend/package-lock.json — 39 commits
- superset-frontend/src — 38 commits
- tests/unit_tests — 29 commits
- superset/mcp_service — 21 commits
- .github/workflows — 19 commits
- (root) — 15 commits
- docs/package.json — 13 commits
- superset-frontend/packages — 12 commits
- superset-frontend/plugins — 11 commits
- superset-websocket/package-lock.json — 10 commits
- superset/commands — 8 commits
- superset-embedded-sdk/package-lock.json — 7 commits
- superset/db_engine_specs — 7 commits
- superset/versioning — 7 commits
- docs/docs — 5 commits
- superset/models — 5 commits
- docs/static — 4 commits
- superset/connectors — 4 commits
- superset/migrations — 4 commits
- superset/utils — 4 commits
Notable commits
- fix: fix(api): align sort and prophet option schemas with their operations (#43206)
- fix: fix(api): enforce is_managed_externally on chart/dashboard/dataset update (#44025)
- fix: fix(api): restore three schema fields disabled by a stray trailing comma (#43225)
- fix: fix(bigquery): avoid ESCAPE clause in column-value typeahead search (SC-121408) (#44429)
- fix: fix(chart): allow semantic view datasource when saving charts (#44169)
- fix: fix(chart): include Decimal metrics in contribution totals (#43222)
- fix: fix(chart): require edit rights for query-context-only updates (#44494)
- fix: fix(chart-controls): keep axis sort available for columns with unknown type (#44344)
- fix: fix(chart-controls): type post-processing columns as a string-to-string mapping (#43589)
- fix: fix(chart-data): keep non-numeric columns out of contribution post-processing (#43203)
- fix: fix(charts): align week-grain time comparison offsets to whole weeks (#43936)
- fix: fix(charts): allow saving charts on semantic views (create/update rejected non-table datasource types) (#44416)
- fix: fix(charts): don't auto-migrate table charts to ag-grid-table on import unless enabled (#44151)
- fix: fix(charts): guard set_related_perm against unknown datasource_type (#43885)
- fix: fix(charts): type-aware datasource access parity for the chart list (#43848)
- fix: fix(ci): align Docker image publishing policy (#44250)
- fix: fix(ci): align superset-cache tag consumers with the Dockerfile PY_VER (#44534)
- fix: fix(ci): give the db2 testcontainer boot real wait headroom (#44399)
- fix: fix(ci): make check_pot_drift extract from an isolated git snapshot (#44578)
- fix: fix(ci): match migration conflicts on filename, not contents_url (#44318)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
apache/superset was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 05017968378f81e44071f44aa16796ec5d2e0b9a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.