Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 20 additions & 18 deletions .github/workflows/build-cli-artifacts.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -21,8 +21,8 @@ on:
required: false
type: string
default: blacksmith-32vcpu-ubuntu-2404
cache_key_suffix:
description: Suffix to distinguish build artifact cache producers
artifact_name_suffix:
description: Suffix to distinguish build artifact producers (e.g. -github)
required: false
type: string
default: ""
Expand DownExpand Up@@ -124,23 +124,25 @@ jobs:
ls -la dist/


- name: Check existing build artifacts cache
id: build-artifacts-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
# Hand the build off to the smoke/publish/brew/scoop jobs via a run-scoped
# artifact rather than a cache. Caches share a 10 GB per-repo budget and
# are evicted LRU, so a large build cache could vanish mid-run between the
# producer and a later consumer (e.g. publish), failing the restore.
# Artifacts have their own deterministic retention and survive job re-runs
# within the run, which is exactly what this handoff needs.
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.artifact_name_suffix }}
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
lookup-only: true

- name: Save build artifacts cache
if: steps.build-artifacts-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}${{ inputs.cache_key_suffix }}-v1
enableCrossOsArchive: true
# Intra-run handoff, not a kept deliverable — expire it the next day.
retention-days: 1
# A full re-run of this job replaces its own artifact instead of
# failing on the duplicate name from the previous attempt.
overwrite: true
# dist/* is already compressed (tar.gz/zip/deb/rpm/apk); a light level
# trims the raw bin/ binaries without burning CPU re-packing the rest.
compression-level: 1
if-no-files-found: error
12 changes: 5 additions & 7 deletions .github/workflows/cli-go-mirror.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,13 +7,11 @@ name: Mirror Dependencies
# ghcr.io, and AWS ECR.

on:
# We can't trigger the mirror job on PR merge because certain tests would fail
# until we mirror some images. E.g. a PR to update the imgproxy image version
# would fail, because there is a test that creates a container from the
# updated image version, which would fail because the image hasn't been
# mirrored yet. It's a catch-22!
#
# TODO: Make the cli start test run *after* we mirror images (if needed).
# This workflow is the manual/bulk entry point for re-mirroring everything.
# Template image bumps are mirrored automatically by mirror-template-images.yml
# on push to develop, which backfills any unmirrored tag when the templates
# Dockerfile changes — so develop and PRs rebased on it stop inheriting the
# `manifest unknown` failure in the ghcr.io-pinned `Start` check.
workflow_dispatch:
permissions:
contents: read
Expand Down
83 changes: 83 additions & 0 deletions .github/workflows/mirror-template-images.yml
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
name: Mirror template images

# Keeps the ghcr.io/ECR mirror in sync with the image versions pinned in
# apps/cli-go/pkg/config/templates/Dockerfile (the single source of truth for
# `config.Images`). When the Dockerfile changes on develop — most often via a
# merged dependabot `docker` bump — this workflow detects any tag that is not
# yet mirrored and backfills it the same way `cli-go-mirror-image.yml` does.
#
# It runs on `push` to develop (not on the PR) on purpose: mirroring needs the
# AWS role + packages:write, which a dependabot-triggered `pull_request` run
# cannot be granted, and we deliberately avoid `pull_request_target`. The CI
# `Start` job pins SUPABASE_INTERNAL_IMAGE_REGISTRY=ghcr.io, so it only goes
# green once a bumped tag is mirrored here; this backfill runs as soon as the
# bump lands on develop, repopulating ghcr.io/ECR so develop and any PR rebased
# on it pass `Start` instead of inheriting a `manifest unknown` failure.

on:
push:
branches:
- develop
paths:
- apps/cli-go/pkg/config/templates/Dockerfile
workflow_dispatch:

permissions:
contents: read

concurrency:
group: mirror-template-images-${{ github.ref }}
cancel-in-progress: false

jobs:
detect:
name: Detect unmirrored images
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
outputs:
missing: ${{ steps.detect.outputs.missing }}
steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false

- name: Setup
uses: ./.github/actions/setup
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Log in to ghcr.io
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Parses the Dockerfile, checks each image against the mirror, and writes
# `missing=<json>` to $GITHUB_OUTPUT. Idempotent: already-mirrored images
# are skipped, so a re-run produces an empty list.
- name: Detect images missing from the mirror
id: detect
run: pnpm exec bun apps/cli/scripts/detect-unmirrored-images.ts

mirror:
name: Mirror image
needs: detect
if: needs.detect.outputs.missing != '' && needs.detect.outputs.missing != '[]'
permissions:
contents: read
packages: write
id-token: write
strategy:
fail-fast: false
matrix:
image: ${{ fromJson(needs.detect.outputs.missing) }}
# Reuse the existing mirror logic (docker.io -> public.ecr.aws + ghcr.io).
uses: ./.github/workflows/cli-go-mirror-image.yml
with:
image: ${{ matrix.image }}
secrets:
PROD_AWS_ROLE: ${{ secrets.PROD_AWS_ROLE }}
11 changes: 3 additions & 8 deletions .github/workflows/publish-preview-cli-packages.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -57,15 +57,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore preview build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download preview build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-legacy-${{ env.PREVIEW_VERSION }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-legacy-${{ env.PREVIEW_VERSION }}

- name: Prepare package files
run: |
Expand Down
84 changes: 31 additions & 53 deletions .github/workflows/release-shared.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -75,7 +75,7 @@ jobs:
version: ${{ inputs.version }}
shell: ${{ inputs.shell }}
runner: large-linux-x86
cache_key_suffix: -github
artifact_name_suffix: -github
timeout_minutes: 45
build_timeout_minutes: 20
secrets:
Expand DownExpand Up@@ -109,15 +109,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}

# Docker's classic image store keeps a single platform manifest per
# tag, so pulling `alpine:3.21` for amd64 and again for arm64 leaves
Expand DownExpand Up@@ -245,15 +240,10 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true
Expand DownExpand Up@@ -304,15 +294,17 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

# Artifacts are zipped and do not carry Unix permissions, so the compiled
# binaries arrive without the executable bit. publish.ts ships
# packages/cli-*/bin/supabase to npm verbatim, so restore +x before
# publishing or the installed CLI would not be runnable.
- name: Fix binary permissions
run: chmod +x packages/cli-*/bin/supabase || true

- name: Sync versions
run: pnpm exec bun apps/cli/scripts/sync-versions.ts --version "${VERSION}"
Expand DownExpand Up@@ -450,8 +442,6 @@ jobs:
publish-homebrew:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -468,21 +458,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here produced a formula whose sha256 rejected the
# downloaded archive ("Formula reports different checksum").
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Homebrew tap token
id: app-token
Expand DownExpand Up@@ -513,8 +498,6 @@ jobs:
publish-scoop:
needs: publish
if: ${{ !inputs.dry_run && inputs.publish_brew_scoop }}
# github-hosted to share a cache store with build-github/publish, whose
# -github-v1 artifacts this job's checksums must match.
runs-on: ubuntu-latest
timeout-minutes: 30
env:
Expand All@@ -531,21 +514,16 @@ jobs:
with:
dependency-firewall-token: ${{ secrets.DF_FIREWALL_TOKEN }}

# Must restore the github-hosted build (-github-v1), the same artifacts
# the publish job uploads to the GitHub Release. The Bun-compiled binaries
# are not byte-for-byte reproducible across the blacksmith and github
# builds, so the blacksmith dist/checksums.txt does not match the released
# Must download the github-hosted build (-github), the same artifacts the
# publish job uploads to the GitHub Release. The Bun-compiled binaries are
# not byte-for-byte reproducible across the blacksmith and github builds,
# so the blacksmith dist/checksums.txt does not match the released
# tarballs. Reading it here would produce a manifest whose hash rejects the
# downloaded archive.
- name: Restore build artifacts cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
- name: Download build artifacts
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: |
packages/cli-*/bin/
dist/
key: cli-build-${{ github.run_id }}-${{ inputs.shell }}-${{ inputs.version }}-github-v1
enableCrossOsArchive: true
fail-on-cache-miss: true
name: cli-build-${{ inputs.shell }}-${{ inputs.version }}-github

- name: Generate Scoop bucket token
id: app-token
Expand Down
Loading
Loading