Skip to content
CAI
Software that uses CAICheck a score

supabase/supabase

48.4

Weak · 28 September 2026

723k

lines of production code

TypeScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive monorepo for the Supabase platform, housing a suite of web applications including the Studio dashboard, documentation, knowledge base, and learning resources. It provides a shared infrastructure of UI components, design tokens, and developer tooling to ensure consistency across the ecosystem. The codebase also includes a library of framework-specific integration examples and AI-powered utilities for documentation and SQL assistance.

How it got here

2019–2022 — Monorepo migration and UI standardization

20 changes.

The project restructured into a pnpm Turborepo monorepo, establishing shared packages for UI components, common infrastructure, and centralized data. This period focused on migrating applications to modern frameworks like Next.js App Router and Tailwind v4, while removing legacy codebases and updating all example projects to use Supabase v2 clients.

2023–2024 — Design system and example expansion

27 changes.

This period focused on establishing a comprehensive design system registry and documentation site, alongside significant updates to the Studio interface and developer tooling. It also saw the introduction of new example applications for Flutter, Next.js, and Kotlin, as well as the launch of AI-powered documentation and SQL debugging utilities.

2025–2026 — UI library expansion and testing infrastructure

24 changes.

This period focused on expanding the UI library with new Vue and Nuxt.js blocks, including authentication, file uploads, and real-time presence components, while introducing dedicated Lite Studio and Knowledge Base applications. Significant effort was also directed toward strengthening test coverage through comprehensive Playwright E2E suites for Studio and Docs, alongside unit tests for core Studio features. The work included updating authentication examples for modern framework versions and standardizing client configurations.

Features

Add Flutter Figma clone example app

Introduces a new Flutter-based example application that demonstrates real-time collaborative drawing. The app includes a login page for user authentication, a project listing page, and an interactive canvas where multiple users can draw circles and rectangles simultaneously. It leverages Supabase for data persistence and real-time broadcasting to sync cursor positions and canvas objects across connected clients.

examples/auth/flutter-mfa, examples/realtime/flutter-figma-clone · high confidence

Add Flutter native Google Auth example

Added a new example application in \examples/auth/flutter-native-google-auth\ that demonstrates how to implement native Google Sign-In for Flutter using the \google\_sign\_in\ package and Supabase's \signInWithIdToken\ API. The example includes a login screen that handles the OAuth flow and a profile screen that displays user metadata and supports sign-out.

examples/auth/flutter-native-google-auth, examples/oauth-app-authorization-flow · high confidence

Add Hono-based Supabase authentication example

Introduces a new example application demonstrating how to integrate Supabase authentication with the Hono web framework. The example includes a server-side middleware for handling Supabase sessions via cookies, a client-side React component for anonymous sign-in and user detail retrieval, and API routes for fetching user claims and database records.

examples/auth/hono · high confidence

Add Next.js Todo List example with Supabase integration

A new Next.js-based todo list example has been added to the examples directory. It includes a Supabase client initialization using the publishable key and defines a TypeScript schema for the 'todos' table, specifying fields for id, task, is\_complete, user\_id, and inserted\_at.

examples/todo-list/nextjs-todo-list · high confidence

A new example application has been added at \examples/user-management/refine-user-management\ that demonstrates user management using the Refine framework and Supabase. The app implements email-based magic link login via a dedicated auth provider and login component, allows users to view and edit their profile (username, website, avatar) using Refine's form hooks, and supports avatar uploads to Supabase storage. It is configured with a dark theme, responsive CSS grid, and React Router for navigation between the login and account pages.

examples/user-management/refine-user-management · high confidence

Add Supabase Edge Functions test client application

A new React-based test client has been added to the examples/edge-functions directory, providing a user interface to invoke and test Supabase Edge Functions. The application includes authentication (sign-in/sign-up) to demonstrate Row Level Security (RLS) in action, a dropdown to select specific functions (such as 'browser-with-cors', 'select-from-table-with-auth-rls', and 'send-email-smtp'), and a JSON editor for request bodies. It is configured with Tailwind CSS for styling and uses the supabase-js client to interact with the functions.

examples/edge-functions · high confidence

Add SvelteKit todo-list example with Supabase integration

A new SvelteKit-based todo-list example has been added to the examples directory. It demonstrates a full-stack application using Supabase for authentication (including email/password and OAuth providers like GitHub and Google) and database operations. The example includes components for login, todo management (add, complete, delete), and a typed database schema, styled with Tailwind CSS.

examples/todo-list/sveltejs-todo-list · high confidence

Add dev toolbar for telemetry and feature flag management

A new Dev Toolbar is now available in local and staging environments, providing a draggable trigger button that opens a panel with 'Events' and 'Flags' tabs. The toolbar displays real-time client and server telemetry events (with copy-to-clipboard support) and allows developers to view and override feature flag values. It respects a \devToolbarDefaultOn\ feature flag and persists its enabled state and position in localStorage, while remaining completely tree-shaken out of production builds.

packages/dev-tools · high confidence

Add product and product list presentation layers to the Supabase sample app

The example app now includes the UI and view-model logic for managing products. Users can add new products via a form that handles loading, success, and failure states, and view their inventory in a list that supports swipe-to-dismiss deletion and pull-to-refresh. This change introduces the presentation components (contracts, screens, view models, and composables) for these features within the sample application.

examples/product-sample-supabase-kt/app/src/main/java/com/example/manageproducts/presentation/feature/addproduct, examples/product-sample-supabase-kt/app/src/main/java/com/example/manageproducts/presentation/feature/productlist · high confidence

Added type definitions for assets, navigation, and unist nodes

New TypeScript declaration files have been added to the design-system types package to support asset imports, navigation structures, and unist tree processing. The \assets.d.ts\ file enables TypeScript to recognize CSS and SCSS modules as style objects. The \nav.ts\ file defines interfaces for navigation items (\NavItem\, \MainNavItem\, \SidebarNavItem\) and their hierarchical variants, including properties for sorting and labeling. The \unist.ts\ file provides types for unist nodes and trees, extending the base Node interface with specific properties for raw strings, class names, events, and npm command markers.

apps/design-system/types · high confidence

Automated generation of the design system registry output

A new build script (\build-registry.mts\) has been added to the design system to automatically generate the public registry output. This tool processes component source files, extracts metadata such as import dependencies and \x-chunk\ attributes, and writes the resulting registry index and chunked component files to the \public/registry\ directory, ensuring the registry stays synchronized with the source code.

apps/design-system/scripts · high confidence

Expanded design system component examples

The design system registry now includes a comprehensive set of new demo files for the \apps/design-system/registry/default/example\ location, providing ready-to-use implementation patterns for users. These additions cover a wide range of UI components, including Accordion, Admonition (with responsive, sandwiched, and button-action variants), Alert Dialogs (supporting async actions and error states), Breadcrumbs (with dropdown and responsive drawer fallbacks), Buttons (demonstrating all variants, sizes, icons, and split-button patterns), Calendar (integrated with React Hook Form), and Charts (bar charts with axis, grid, and legend configurations). This gives developers concrete examples for integrating these specific components into their applications.

apps/design-system/registry/default/example · high confidence

Introduce @supabase/pg-meta package for safe catalog introspection

The new @supabase/pg-meta package provides a centralized, type-safe interface for Postgres catalog introspection used by the Studio dashboard. It replaces manual SQL construction with a \SafeSqlFragment\ system that prevents SQL injection and enforces proper escaping of identifiers and literals. The package includes comprehensive builders for tables, columns, indexes, functions, policies, and more, all scoped to specific objects to prevent performance regressions on large catalogs. It also includes a plan guard test suite to ensure introspection queries remain efficient and don't perform unscoped sequential scans on system catalogs.

packages/pg-meta · high confidence

Introduce AI-powered documentation assistant and SQL debugging tools

The new \ai-commands\ package provides a set of AI-driven capabilities for Supabase users. The \clippy\ function acts as a documentation assistant, using RAG to answer user questions based on Supabase docs and returning source references. Additionally, the package introduces SQL utilities: \debugSql\ automatically fixes Postgres errors and suggests corrections, \titleSql\ generates descriptive titles and summaries for SQL snippets, and \generateCron\ converts natural language descriptions into valid \pg\_cron\ expressions. These features are implemented using the OpenAI API (defaulting to \gpt-4o-mini\) and are exposed via specific entry points, with streaming functions available through the \edge\ subpath.

packages/ai-commands · high confidence

Introduce Lite Studio app for lightweight project management

A new 'Lite Studio' application has been added to the monorepo, providing a streamlined interface for managing Supabase projects. Built on React Router with Tailwind CSS, it features a dark-themed UI and includes a project overview page with tabs for Database and Settings. Users can view project status, manage tables, and toggle Row Level Security (RLS) settings. The app is configured for Docker deployment and includes a welcome screen with navigation resources.

apps/lite-studio · high confidence

Introduce design-system configuration files for site metadata and documentation navigation

Added \apps/design-system/config/site.ts\ and \apps/design-system/config/docs.ts\ to centralize the Supabase Design System's site metadata (name, URL, social links, and credits) and documentation sidebar structure. The \docs.ts\ file defines the navigation hierarchy for the design system documentation, including sections for Getting Started, UI Patterns, and Fragment Components, establishing the foundational configuration for the design system's documentation site.

apps/design-system/config · high confidence

Introduce the Knowledge Base (kb) application

Adds a new Astro-based application at apps/kb to host Supabase's knowledge base, featuring a homepage with a hero section, a navigation bar with topic and resource menus, and a footer with support links. The app renders guides from src/content/guides using a custom layout that supports GitHub-Flavored Markdown, including admonitions (alerts) and a Supabase-branded code block theme. It also exposes topic pages and provides a pre-build script to export all content as plain Markdown files for external consumption.

apps/kb · high confidence

Introduction of the shared \`packages/ui\` component library

The \packages/ui\ directory has been established as the central repository for Supabase's shared React component library, built on Radix UI primitives and shadcn/ui, and styled with Tailwind CSS. This location now provides the core design system infrastructure, including a new OKLCH-based semantic color system (\semantic.css\) with explicit light and dark theme definitions, backwards-compatibility aliases (\compat.css\), and a comprehensive set of exported UI components (such as Button, Input, Dialog, and various shadcn primitives) alongside utilities like \cn\ and \clipboard\. The package also includes specific application components like \AnimatedCounter\ and \ThemeProvider\, serving as the single source of truth for UI patterns across the monorepo.

packages/ui · high confidence

Launch of the new Supabase Learn application

The \apps/learn\ directory now contains a fully functional Next.js application for the Supabase Learn platform. This new app provides a structured learning experience with a home page listing four distinct courses (Supabase Foundations, Smart Office Project, and two Internals courses), a dynamic documentation reader powered by Velite for MDX content, and interactive features such as chapter completion tracking, a command palette for navigation, and copy-to-clipboard functionality for code snippets. The implementation includes a dedicated layout with sidebar navigation, theme switching, and telemetry integration, replacing the previous static or separate setup for this content.

apps/learn · high confidence

New CI/CD and developer tooling scripts for Vercel, Tailwind, and security

This change introduces a suite of new scripts to the \scripts/\ directory to improve deployment reliability, developer experience, and security posture. \authorizeVercelDeploys.ts\ and \waitForVercelPreview.js\ automate the authorization and URL resolution of Vercel preview deployments, with the latter including a fallback mechanism for skipped builds and a corresponding test suite (\waitForVercelPreview.test.js\). \upload-static-assets.sh\ offloads static assets to a Cloudflare R2 CDN to reduce egress costs and latency. \bump-package.ts\ and \fix-audit-vulnerability.ts\ provide an interactive workflow to identify and patch vulnerable dependencies by updating the pnpm lockfile. \tw-rename-utilities.ts\ assists in migrating code to Tailwind CSS v4 by renaming changed utility classes, while \check-case-hazards.mjs\ prevents cross-platform filesystem issues by detecting case-sensitivity collisions. Supporting scripts \generateLocalEnv.js\ and \getSecrets.js\ streamline local environment configuration and secret retrieval.

scripts · high confidence

New SolidJS user management example with Supabase integration

Added a complete SolidJS example for user management in the \examples/user-management/solid-user-management\ directory. The example demonstrates email-based magic link authentication and profile management (including avatar uploads) using the Supabase JavaScript client. It includes the necessary React/Solid components (\App\, \Auth\, \Account\, \Avatar\), a Supabase client configuration using environment variables, and a TypeScript schema definition for the user profiles database table.

examples/user-management/solid-user-management · high confidence

New TanStack DB block for auto-generating CRUD interfaces

The UI Library now includes a new TanStack DB block that automatically generates a full CRUD (Create, Read, Update, Delete) interface for your Supabase database tables. By providing your project reference and anonymous key, the library fetches your database schema and generates a list view, a detail/edit sheet, and the necessary database collection and schema files. This allows you to quickly scaffold a functional admin or data-management interface directly from your existing database structure.

apps/ui-library · high confidence

New UI patterns package with Admonition, Assistant Chat, and Announcement components

The \packages/ui-patterns\ package has been introduced to centralize UI components that rely on external NPM libraries (like \react-markdown\ and \reactflow\) or combine multiple \ui\ package components. This location now provides the \Admonition\ component, which supports multiple types (note, warning, danger, etc.), layouts (vertical, horizontal, responsive), and accessible alert roles. It also includes the \AssistantChat\ components (\AssistantChatForm\ and \AssistantCommandsPopover\) for AI-driven text input with command suggestions, and the \AnnouncementBanner\ component which displays the Select 2026 promotion with local storage-based dismissal persistence.

packages/ui-patterns · high confidence

New Vue and Nuxt.js starter blocks for Supabase integration

This release introduces a new set of Vue and Nuxt.js starter blocks for the UI library, providing ready-to-use components and composable patterns for common Supabase workflows. The new blocks include password-based authentication (login, sign-up, and password reset forms), a current-user avatar component, a dropzone for file uploads to Supabase Storage, and an infinite query composable for paginated data fetching. These blocks are registered in the shadcn-style registry and include the necessary UI primitives (Button, Input, Card, Avatar, Tooltip) and Supabase client configurations for both Vue and Nuxt.js environments.

blocks · high confidence

New Vue/Nuxt avatar and realtime presence components

Added a \current-user-avatar\ component that displays the logged-in user's profile image and initials, along with a \realtime-avatar-stack\ that shows a stack of avatars for users currently present in a Supabase Realtime room. The stack component supports configurable orientation, a maximum visible avatar count, and tooltips for hidden users, while the underlying \useRealtimePresenceRoom\ composable manages room subscription and user tracking.

blocks/vue/registry/default/current-user-avatar/nuxtjs, blocks/vue/registry/default/realtime-avatar-stack/nuxtjs · high confidence

New Vue/Nuxt dropzone and realtime cursor components

Added new UI components and composables for the Nuxt.js registry: a file upload dropzone block (including \dropzone.vue\, \dropzone-content.vue\, \dropzone-empty-state.vue\, and a \useSupabaseUpload\ composable for handling file validation and Supabase storage uploads) and a realtime cursor block (including \cursor.vue\, \realtime-cursors.vue\, and a \useRealtimeCursors\ composable that tracks and broadcasts mouse positions via Supabase Realtime).

blocks/vue/registry/default/dropzone/nuxtjs, blocks/vue/registry/default/realtime-cursor/nuxtjs · high confidence

New agent skills for API types and docs-app architecture

Added new agent skills to guide contributors on maintaining generated Supabase API types (including local and production verification workflows) and to provide a comprehensive reference for the \apps/docs\ architecture, build pipeline, and feature-design best practices.

.agents · high confidence

New design-system documentation components and utilities

The design-system app now includes a suite of new components to enhance the documentation site, including a Command Menu for quick navigation and theme switching, a Color Palette viewer with copy-to-clipboard functionality, and interactive Component Previews that display live examples alongside their source code. Additional utilities such as a Callout component, Code Block Wrapper, and MDX component mappings have been added to support richer documentation content, while navigation aids like the Docs Pager and Side Navigation components improve content discoverability.

apps/design-system/components · high confidence

New design-system registry for component installation

The design-system registry has been initialized with a new structure that defines how UI components, examples, charts, and fragments are cataloged and installed. This includes a Zod-based schema for registry entries, configuration files for ESLint and style themes (Zinc, Slate, Stone, Gray), and registry manifests for UI primitives (like accordion, button, dialog), interactive chart blocks, copy-writing examples, and layout fragments. This enables consistent, automated installation of design-system components into applications.

apps/design-system/registry · high confidence

New design-system styles for code blocks, MDX, and global theming

The design-system styles package now includes dedicated CSS files to standardize the appearance of code blocks, MDX content, and global layout. A new \code-block-variables.css\ defines syntax-highlighting tokens for both light and dark themes, ensuring consistent code rendering. \mdx.css\ styles MDX-generated content, including code fragments with line numbers and highlighted lines, as well as step-based content. \globals.css\ establishes the base theme using Tailwind v4 configuration, setting up font stacks (Inter, Manrope, Source Code Pro), text sizing optimized for Inter, and base utility classes for smooth scrolling and border styling.

apps/design-system/styles · high confidence

New generator package for processing documentation specs

A new \packages/generator\ package has been added to the repository. It includes utility functions for string manipulation and file I/O, and provides a CLI tool (\tsdoc.ts\) that reads a JSON specification file, dereferences type definitions (specifically for parameters, properties, and union types), and writes the processed output to disk.

packages/generator · high confidence

New homepage and layout for the Design System site

The Design System application now features a dedicated homepage and a unified layout structure. The new layout includes a 'Skip to Content' link for accessibility, a top navigation bar, a mobile sidebar sheet, a fixed side navigation area, and a site footer. The homepage itself serves as a central hub, providing direct links to key documentation sections including Colors, Icons, Theming, UI patterns, Fragment components, and Atom components.

apps/design-system/app/(app) · high confidence

New icons package with build tooling and registry

A new \packages/icons\ package has been introduced to manage custom Supabase icons. It includes a build system (\packages/build-icons\) that generates React components from SVG files, supports icon aliases and dynamic imports, and produces a centralized registry (\\_\registry\\_/index.tsx\) for discovery and lazy loading. Users can now add custom icons by placing SVGs in \src/raw-icons/\ and running the build script.

packages/icons · high confidence

New interactive and composed chart block components

The design system registry now includes a suite of new chart block components in the \apps/design-system/registry/default/block\ directory. These additions provide ready-to-use patterns for data visualization, including an interactive bar chart with toggleable series (\chart-bar-interactive\), a comprehensive set of composed chart blocks (\chart-composed-\*\) that demonstrate various states (loading, empty, error, disabled), metrics integration, table footers, and dynamic type switching. Additionally, \chart-palette\ and \chart-palette-stress\ serve as visual references for the chart color token system and stress-test multi-series rendering capabilities.

apps/design-system/registry/default/block · high confidence

New internal fixtures and AWS Bedrock AI examples

Added a new \\_internal\ directory containing JavaScript, Python, and TypeScript fixture files for internal testing purposes. Additionally, introduced two new AI examples: \aws\_bedrock\_image\_gen\, which demonstrates generating images via Amazon Bedrock and storing them in Supabase Storage, and \aws\_bedrock\_image\_search\, which implements semantic image search using Amazon Titan Multimodal Embeddings and Supabase Vector.

examples · high confidence

New reusable marketing form system with multi-CRM fan-out and anti-spam protections

The \packages/marketing\ package now provides a reusable \MarketingForm\ component and a server-side submission pipeline that fans out form data to HubSpot, Customer.io, and Notion in parallel. To ensure security, the client only posts a form reference (\slug\ and \formId\); the server resolves the actual CRM credentials from a trusted registry, preventing client-side tampering. The system includes built-in anti-spam measures such as honeypot fields, minimum render-time checks, and deduplication for Notion submissions. Additionally, a \HubSpotFormEmbed\ component is available for rendering HubSpot-hosted forms directly, and the package exposes schemas and sections for building structured \/go\ pages.

packages/marketing · high confidence

New self-hosted Docker configuration reference and example environment file

The self-hosted Docker setup now includes a comprehensive configuration reference (CONFIG.md) and a complete example environment file (.env.example) that documents all supported environment variables for services like Studio, Auth, PostgREST, and Supavisor. This addition clarifies required secrets, default values, and configuration options for operators deploying Supabase via Docker Compose.

docker · high confidence

New shared common package for authentication, theming, and feature flags

A new \packages/common\ directory has been introduced to centralize shared frontend infrastructure across the Supabase applications. This package provides a unified \AuthProvider\ and associated React hooks (such as \useUser\ and \useIsLoggedIn\) built on top of GoTrue, ensuring consistent session management. It also includes a \ThemeProvider\ that standardizes dark/light mode handling and includes logic to migrate legacy theme preferences, alongside a \FeatureFlagProvider\ and \useFlag\ hook for centralized ConfigCat integration. Additionally, the package offers reusable components for managing favicons in both Next.js App Router and Pages Router contexts, as well as a shared set of Supabase logo assets.

packages/common · high confidence

Supabase project scaffolding and documentation search infrastructure

This change introduces the initial Supabase project configuration and the database schema and edge functions required for documentation search. The \config.toml\ sets up the local development environment, including API and database ports, and configures authentication providers (Apple, GitHub) and email signup settings. It also defines the \og-images\ edge function for generating social media preview images. The database migrations establish the core tables for documentation search (\page\, \page\_section\), vector similarity search using \pgvector\, and full-text search (FTS) with ranking logic. Additionally, it adds tables for user feedback (\feedback\), tracking content changes (\last\_changed\), and a ticketing system for Launch Weeks (\launch\_weeks\, \tickets\).

supabase · high confidence

Unified API type definitions and production verification tooling

The \packages/api-types\ package now consolidates TypeScript definitions for the API v1, API v2, and Platform services into a single exported interface, allowing consumers to access all API schemas, operations, and paths from one location. Additionally, a new verification script (\verify-production-types.mjs\) and its tests have been added to the package; this tool fetches the live OpenAPI specifications from production endpoints, regenerates the TypeScript types, and compares them against the committed files to ensure the local type definitions remain in sync with the live API.

packages/api-types · high confidence

Removals

Supabase web site codebase removed

The entire \packages/web\ directory has been deleted, removing the legacy Next.js-based landing page, documentation, and associated assets. This includes the removal of the main layout components (Navbar, Footer, MainLayout), the MobX state management store, the Bulma-based SCSS styles, and the static site configuration files (next.config.js, babel.config.js).

packages/web · high confidence

Architecture

Repository initialized as a pnpm 11 Turborepo monorepo with Node 22

The repository has been restructured into a Turborepo monorepo managed by pnpm v11, requiring Node.js 22.13 or later. This change introduces a new workspace structure with apps (studio, docs, www, design-system, ui-library, lite-studio, kb, learn) and shared packages (ui, ui-patterns, common, api-types, pg-meta, shared-data). Development workflows now use pnpm commands (e.g., pnpm dev:studio, pnpm e2e) and the monorepo enforces strict dependency management via pnpm catalogs, exotic subdependency blocking, and minimum release age policies. New configuration files include .coderabbit.yaml for AI-assisted code reviews, knip.jsonc for dead code detection, and AGENTS.md/DEVELOPERS.md for contributor guidance.

(repo-wide) · high confidence

Behavioural changes

Angular user management example updated to use Angular forms and Supabase v2

The Angular user management example has been rewritten to use the Angular \ReactiveFormsModule\ for form handling, replacing previous approaches. The application now uses the Supabase JavaScript client v2 API for authentication (magic link sign-in) and profile management. The UI includes dedicated components for authentication, account profile editing (username, website, avatar), and avatar upload, all wired through a central \SupabaseService\.

examples/user-management/angular-user-management · high confidence

Automated formatting and linting for Claude Code sessions

Claude Code now automatically formats and lints code after every file write or edit. A new settings configuration registers a PostToolUse hook that runs a script to apply Prettier formatting to supported file types (TypeScript, JavaScript, CSS, Markdown, etc.) and ESLint fixes for JS/TS files within configured apps and packages. Additionally, a SessionStart hook ensures dependencies are installed via pnpm when running in a remote environment, and a symlink to skills is established to support skill triggering.

.claude · high confidence

Centralize compute disk limits and pricing data in shared-data package

The \packages/shared-data\ module now serves as the single source of truth for core product configuration, introducing centralized definitions for compute disk performance limits (IOPS and throughput per instance size), detailed pricing structures across Free, Pro, Team, and Enterprise plans, and Auth rate limits. This change consolidates previously scattered data into a shared library, ensuring consistent display of disk capabilities, plan features, and usage limits across the dashboard and documentation.

packages/shared-data · high confidence

Design-system documentation engine migration to Velite

The design-system documentation engine has been rebuilt to use Velite instead of Contentlayer2. This introduces a new server-side data layer (in \apps/design-system/lib/docs.ts\) that loads document metadata and code snippets from the \.velite\ output directory, and adds MDX rendering support via \use-mdx-component.ts\ to execute compiled MDX code. To support this, new utility modules handle table-of-contents generation (\toc.ts\), MDX-to-HTML remark plugins (\remark-jsx-components.ts\), and component source injection via rehype plugins (\rehype-component.ts\, \rehype-npm-command.ts\). The change also adds configuration for the Supabase theme (\themes/supabase-2.json\), font definitions (\fonts.ts\), and a base-path constant (\constants.ts\), enabling the design-system site to render documentation with improved build-time performance and local dev reload.

apps/design-system/lib · high confidence

Flutter user management example updated to use Supabase Flutter v2

The Flutter user management starter example has been rewritten to use the supabase\_flutter v2 API. This update introduces a new authentication flow using magic links (OTP) instead of previous methods, adds a profile management page with avatar upload capabilities via Supabase Storage, and implements proper error handling with snackbar notifications for both authentication and database operations. The app now initializes using environment variables for configuration and includes a splash page for session state redirection.

examples/user-management/flutter-user-management · high confidence

Migrate design system configuration to Tailwind v4 CSS format

The \packages/config\ directory has been restructured to support Tailwind v4 by migrating all configuration from JavaScript files to native CSS. The previous \tailwind.config.js\ and \ui.config.js\ files have been replaced by a modular set of CSS files under \packages/config/css/\, including \colors.css\ for the Radix/scale/brand palette, \theme.css\ for semantic design tokens, \animations.css\ for keyframes, and \utilities.css\ for custom classes like \shimmer\ and \hit-area\. The main entry point is now \tailwind.config.css\, which imports these modules and the \@tailwindcss/postcss\ plugin via \postcss.config.js\. This change shifts the design system's definition from JS objects to CSS \@theme\ and \@utility\ rules, ensuring the visual system (colors, typography, variants) is defined in a format native to the new Tailwind version.

packages/config · high confidence

Migrate design-system app to Next.js App Router

The design-system application has been migrated to the Next.js App Router, introducing a new root layout that configures global fonts (Inter, Manrope, Source Code Pro), metadata, and theme colors. This change replaces the previous client-side toast implementation with Sonner for notifications and establishes a new provider hierarchy (Jotai, Theme, Tooltip, Mobile Sidebar) to manage application state and UI context. Supporting infrastructure includes new hooks for configuration persistence, media queries, and mobile sidebar state management.

apps/design-system/app · high confidence

Migrate design-system documentation engine to Velite

The design-system app has replaced its previous content layer with Velite to compile MDX documentation. This change introduces a new build pipeline that generates a lightweight metadata index and separate code JSON files, significantly reducing memory usage and improving local development hot-reload performance for content edits. The configuration includes specific Shiki syntax highlighting themes and registry generation scripts, while the app now requires a local environment variable to set the base path for asset URLs.

apps/design-system · high confidence

Migrate www app to Next.js App Router

The www application has been migrated from the legacy Pages Router to the Next.js App Router. This change updates the underlying routing and rendering architecture, which may affect how server-side rendering and client-side navigation behave for users browsing the documentation and marketing pages.

apps/www · high confidence

New ESLint rules enforce Safari-compatible clipboard usage and explicit keyboard focus

The shared ESLint configuration now includes two new custom rules to improve accessibility and Safari compatibility. The \no-await-before-copy-to-clipboard\ rule flags code that awaits before calling \copyToClipboard\, preventing Safari clipboard failures by ensuring synchronous execution. The \require-explicit-tabindex\ rule enforces explicit \tabIndex\ attributes on raw \\<button\>\ elements and elements with \role="button"\, ensuring they are included in the keyboard focus order. These rules are part of the unified Next.js ESLint config and are set to error level to prevent regressions.

packages/eslint-config-supabase · high confidence

Next.js Slack clone example refactored to use Supabase v2 client and new store architecture

The Next.js Slack clone example has been updated to use the Supabase JavaScript client v2, switching from the anonymous key to the publishable key for initialization. The application's state management has been restructured with a new \Store.js\ module that handles real-time subscriptions for messages, channels, and users, alongside a new \UserContext.js\ for user state sharing, replacing the previous implementation.

examples/slack-clone/nextjs-slack-clone · high confidence

Next.js user management example updated to Next.js 15+ and Supabase SSR helpers

The Next.js user management example has been rewritten to use the App Router and modern Supabase patterns. It now relies on \@supabase/ssr\ for client and server initialization, implements a middleware proxy (\lib/supabase/proxy.ts\) to handle session cookies, and uses \supabase.auth.getClaims()\ in server components to access user data. Authentication flows (login, signup, signout) are handled via Next.js Server Actions and Route Handlers, and the UI includes a profile form with avatar upload support.

examples/user-management/nextjs-user-management · high confidence

React user management example migrated to Vite and Supabase v2

The React user management example has been rebuilt using Vite as the build tool and updated to use the Supabase JavaScript client v2. This migration introduces a new project structure with separate components for authentication (Auth), account management (Account), and avatar handling (Avatar), replacing the previous implementation. The application now uses Vite environment variables (VITE\_SUPABASE\_URL, VITE\_SUPABASE\_PUBLISHABLE\_KEY) for configuration and implements proper cleanup of auth state change listeners to prevent memory leaks. The UI includes a magic link login flow, profile editing with avatar upload to Supabase Storage, and sign-out functionality.

examples/user-management/react-user-management · high confidence

Standardize Supabase environment variable naming in Vue and Nuxt clients

The Vue and Nuxt Supabase client implementations now expect the environment variable \SUPABASE\_PUBLISHABLE\_KEY\ instead of the previous \SUPABASE\_PUBLISHABLE\_OR\_ANON\_KEY\. Users integrating these clients must update their environment configuration to use the new variable name to ensure correct authentication and client initialization.

blocks/vue/registry/default/clients/nuxtjs, blocks/vue/registry/default/clients/vue · high confidence

Studio: Rename Replication to Pipelines

The Studio interface now refers to data replication features as "Pipelines" instead of "Replication". This change updates the navigation labels, page titles, and UI copy throughout the Studio application to reflect the new terminology, aligning the product's language with its current capabilities.

apps/studio · high confidence

Supabase Kotlin sample updated to v2.0.0 with PKCE authentication and deep linking

The product sample app has been refactored to align with the Supabase Kotlin client v2.0.0. This update introduces PKCE-based authentication, configured via the new \FlowType.PKCE\ in the Supabase module, and adds a dedicated \DeepLinkHandlerActivity\ to handle OAuth callbacks securely. The app now uses a clean architecture with Hilt dependency injection, separating data repositories, domain use cases, and presentation layers, while also adding instrumentation tests and ProGuard rules for production readiness.

examples/product-sample-supabase-kt · high confidence

Supabase auth example updated for Next.js 16 proxy and SSR client changes

The Next.js Supabase authentication example has been refactored to align with recent Supabase SSR client updates and Next.js 16 proxy requirements. This includes introducing dedicated client modules for browser and server contexts, implementing a new proxy middleware (\proxy.ts\) that handles session updates and cookie synchronization via the \setAll\ callback, and adjusting server-side client creation to properly manage cookie stores and handle potential errors from Server Components.

examples/auth/nextjs · high confidence

The SvelteKit auth examples have been rewritten to align with SvelteKit 5's cookie API changes and to improve security by validating JWTs locally. The server hooks now explicitly set the cookie path to \/\ in the \setAll\ callback to satisfy SvelteKit's requirements, and the layout loads now use \supabase.auth.getClaims()\ instead of the deprecated \getSession\ or \getUser\ methods to retrieve user identity. This ensures that authentication state is validated against asymmetric signing keys without extra round-trips, and the private routes are protected by a server-side guard that redirects unauthenticated users.

examples/auth/sveltekit, examples/auth/sveltekit-full · high confidence

SvelteKit user management example updated to Svelte 5 and Supabase SSR

The SvelteKit user management example has been rewritten to use Svelte 5 syntax (including $props, $state, and $derived) and the @supabase/ssr library for authentication. This update introduces a server-side hook that properly handles cookie synchronization and header forwarding, replaces the deprecated safeGetSession with getClaims for JWT validation, and implements a complete sign-in flow using magic links instead of previous methods.

examples/user-management/sveltekit-user-management · high confidence

Updated React Native auth quickstart with modern Supabase client setup

The React Native authentication quickstart example now uses a new \lib/supabase.ts\ module that initializes the Supabase client with explicit session persistence and automatic token refresh logic. This implementation adds platform-specific handling for React Native by integrating \@react-native-async-storage/async-storage\ for non-web platforms and listening to \AppState\ changes to manage session auto-refreshing, ensuring sessions remain valid while the app is in the foreground.

examples/auth/quickstarts/react-native · high confidence

Fixes

Fix table column resizing on Safari

Applies a patch to the react-data-grid library to resolve an issue where table editor columns could not be resized in Safari. The change modifies the onLostPointerCapture handler to remove an unnecessary event argument and conditional check, ensuring pointer capture loss is handled correctly across browsers.

patches · high confidence

Test coverage

Add Playwright E2E test suites for Studio and Docs; Added test coverage for the Logs feature area; Added test fixtures for table editor and storage E2E tests; Added tests for AI assistant query visualization and log parsing utilities; Added tests for reports geo-utils and storage-report components; Added tests for the Explain Visualizer parser and utilities.

Dependencies

Adopts 'cn' utility for class merging

The block now imports the 'cn' utility from the 'cn' package to handle class name merging, replacing the previous implementation that relied on clsx and tailwind-merge.

blocks/vue/registry/default · high confidence

New documentation and learning applications added to the monorepo

The monorepo now includes four new application packages: \design-system\, \docs\, \kb\, and \learn\. The \design-system\ app serves as a registry and documentation site for UI components, built with Next.js and Velite. The \docs\ app handles the main Supabase documentation, featuring federated content, reference generation, and search embeddings. The \kb\ app is a new knowledge base site built with Astro. The \learn\ app provides interactive tutorials and learning paths, also using Next.js and Velite. These apps introduce new dependencies such as Velite, Astro, and various MDX/Markdown processing libraries to support content generation and rendering.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 32 → 48 (+16.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 78 → 67 (-10.8)
  • Architecture 42 → 55 (+13.8)
  • Maturity 64 → 72 (+7.8)
  • Readiness 18 → 43 (+24.6)
  • Security 37 → 53 (+16.5)
  • Accessibility 50 (new)
  • Performance 60 (new)

Resolved (106)

  • (anonymous) (cognitive 18) (apps/www/internals/generate-sitemap.mjs)
  • (anonymous) (cyclomatic 18) (apps/www/internals/generate-sitemap.mjs)
  • Coverage not measured — test suite did not build
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dimension evaluation failed
  • FileTooLong: docs/Troubleshooting.script.mjs (apps/docs/features/docs/Troubleshooting.script.mjs)
  • FileTooLong: lib/redirects.js (apps/www/lib/redirects.js)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 86 more

New (3097)

  • AIAssistantChatSelector.AIAssistantChatSelector (cognitive 19) (apps/studio/components/ui/AIAssistantPanel/AIAssistantChatSelector.tsx)
  • AIAssistantChatSelector.AIAssistantChatSelector (cyclomatic 19) (apps/studio/components/ui/AIAssistantPanel/AIAssistantChatSelector.tsx)
  • AIAssistantHeader.AIAssistantHeader (cognitive 16) (apps/studio/components/ui/AIAssistantPanel/AIAssistantHeader.tsx)
  • APIKeys.APIKeys (cognitive 65) (apps/studio/components/interfaces/Project/APIKeys.tsx)
  • APIKeys.APIKeys (cyclomatic 29) (apps/studio/components/interfaces/Project/APIKeys.tsx)
  • AWSPrivateLinkForm.AWSPrivateLinkForm (cognitive 22) (apps/studio/components/interfaces/Settings/Integrations/AWSPrivateLink/AWSPrivateLinkForm.tsx)
  • AWSPrivateLinkForm.AWSPrivateLinkForm (cyclomatic 27) (apps/studio/components/interfaces/Settings/Integrations/AWSPrivateLink/AWSPrivateLinkForm.tsx)
  • AccessToken.roles.applySelectionToRoleContext (cognitive 33) (apps/studio/components/interfaces/Account/AccessTokens/AccessToken.roles.ts)
  • AccessToken.roles.applySelectionToRoleContext (cyclomatic 21) (apps/studio/components/interfaces/Account/AccessTokens/AccessToken.roles.ts)
  • AccessToken.roles.computeTokenRoleContext (cognitive 19) (apps/studio/components/interfaces/Account/AccessTokens/AccessToken.roles.ts)
  • AccessToken.roles.computeTokenRoleContext (cyclomatic 18) (apps/studio/components/interfaces/Account/AccessTokens/AccessToken.roles.ts)
  • AccessToken.utils.filterAndSortTokens (cognitive 20) (apps/studio/components/interfaces/Account/AccessTokens/AccessToken.utils.ts)
  • AccountIdentities.AccountIdentities (cognitive 23) (apps/studio/components/interfaces/Account/Preferences/AccountIdentities.tsx)
  • AccountIdentities.AccountIdentities (cyclomatic 26) (apps/studio/components/interfaces/Account/Preferences/AccountIdentities.tsx)
  • ActionBar.ActionBar (cognitive 19) (apps/studio/components/interfaces/TableGridEditor/SidePanelEditor/ActionBar.tsx)
  • ActionBar.ActionBar (cyclomatic 18) (apps/studio/components/interfaces/TableGridEditor/SidePanelEditor/ActionBar.tsx)
  • Activity.Activity (cognitive 38) (apps/studio/components/interfaces/Observability/DatabaseConnections/Activity.tsx)
  • Activity.Activity (cyclomatic 51) (apps/studio/components/interfaces/Observability/DatabaseConnections/Activity.tsx)
  • ActivityRow.ActivityRow (cognitive 48) (apps/studio/components/interfaces/Observability/DatabaseConnections/ActivityRow.tsx)
  • ActivityRow.ActivityRow (cyclomatic 44) (apps/studio/components/interfaces/Observability/DatabaseConnections/ActivityRow.tsx)
  • …and 3077 more

Changes since last survey

  • 300 commits — 217 feature/other, 83 fixes

By area

  • apps/studio — 159 commits
  • apps/docs — 79 commits
  • apps/www — 19 commits
  • packages/ui — 6 commits
  • apps/ui-library — 5 commits
  • (root) — 4 commits
  • apps/design-system — 4 commits
  • docker/volumes — 4 commits
  • .agents/skills — 3 commits
  • packages/ui-patterns — 3 commits
  • e2e/studio — 2 commits
  • examples/edge-functions — 2 commits
  • packages/common — 2 commits
  • (repo) — 1 commit
  • .github/CODEOWNERS — 1 commit
  • .github/dependabot.yml — 1 commit
  • .github/pull_request_template.md — 1 commit
  • apps/kb — 1 commit
  • docker/CONFIG.md — 1 commit
  • docker/utils — 1 commit

Notable commits

  • fix: Design System: Fix Select does not show its invalid state correctly (#50859)
  • fix: Editor panel fix save snippet (#50262)
  • fix: Fix TextConfirmModal does not reset its state (#50406)
  • fix: Fix sync between filter bar and filter controls in unified logs (#50383)
  • fix: Fix tooltip a11y comment (#50640)
  • fix: Fix types master (#50345)
  • fix: Fix unstable test by increasing its timeout (#50860)
  • fix: Recovery codes: fix condition to display them (#50716)
  • fix: Revert source-map disable from #50579 (re-enable Sentry source maps for studio) (#50581)
  • fix: fix(auth): migrate overview errors to clickhouse (#50174)
  • fix: fix(common): restore narrow Feature type (#50850)
  • fix: fix(deps): add cooldown to npm Dependabot updates to satisfy pnpm minimumReleaseAge (#50417)
  • fix: fix(docker): ship volumes/storage so it is not created as root (#50299)
  • fix: fix(docs): codetabs file tabs (#50811)
  • fix: fix(docs): guide reference perf enhancements (#50239)
  • fix: fix(docs): kotlin codeblock sticky collision (#50566)
  • fix: fix(docs): redirect monitoring-and-debugging to observability (#50576)
  • fix: fix(docs): redirect monitoring-and-debugging.md to observability.md (#50561)
  • fix: fix(o11y): add connections to footer (#50928)
  • fix: fix(o11y): support partial metric loading (#50867)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

supabase/supabase was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fd0918833ff3d8388144c559441abe043239d5c2 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.