Skip to content

feat: add global async query playwright tests - #43004

Merged
sadpandajoe merged 39 commits into
apache:masterfrom
preset-io:test-global-async-query-playwright
Oct 6, 2026
Merged

sadpandajoe merged 39 commits into
apache:masterfrom
preset-io:test-global-async-query-playwright

Conversation

@drivaspreset

Copy link
Copy Markdown
Contributor

SUMMARY

Adds Playwright E2E coverage for Global Async Queries (GAQ) on dashboards and SQL Lab.

Eight dashboard-level tests cover the GAQ request/response lifecycle end to end:

  • Forced dashboard refresh going through the full 202 → poll → done cycle
  • Reloading an already-cached dashboard being served synchronously (never touching the async channel)
  • A broken chart surfacing a clean error under GAQ instead of hanging, and recovering once fixed
  • Rapidly switching a filter value without a superseded (stale) response clobbering the screen
  • A dashboard with many charts resolving every chart independently and correctly
  • Losing the async-token cookie bouncing chart refresh to /login even though the underlying session stays valid
  • Navigating away mid-load and back producing no console errors and re-rendering cleanly
  • A native filter's value dropdown populating through the same async pipeline as chart data

A ninth test (global-async-query-sqllab.spec.ts) runs under the separate chromium-sqllab Playwright project and asserts that a simple SELECT in SQL Lab still runs synchronously with GLOBAL_ASYNC_QUERIES enabled, i.e. that the flag doesn't accidentally route SQL Lab traffic through the GAQ polling endpoint.

dashboard-test-helpers.ts gains an optional chartWidth on createDashboardWithCharts, so tests can lay out more charts per row than the default single-row 12-column grid would otherwise allow (needed for the many-charts test).

BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF

N/A - test-only change, no UI behavior modified.

TESTING INSTRUCTIONS

Requires GLOBAL_ASYNC_QUERIES enabled, plus Redis and a running Celery worker (all tests except the cache-hit-reload case, which is served synchronously and only needs the feature flag).

cd superset-frontend

# dashboard GAQ suite
npx playwright test tests/dashboard/global-async-query.spec.ts

# SQL Lab smoke test (separate project)
npx playwright test tests/sqllab/global-async-query-sqllab.spec.ts --project=chromium-sqllab

ADDITIONAL INFORMATION

  • Has associated issue:
  • Required feature flags: GLOBAL_ASYNC_QUERIES
  • Changes UI
  • Includes DB Migration (follow approval process in SIP-59)
    • Migration is atomic, supports rollback & is backwards-compatible
    • Confirm DB migration upgrade and downgrade tested
    • Runtime estimates and downtime expectations provided
  • Introduces new feature or API
  • Removes existing feature or API

@dosubot dosubot Bot added the global:async-query Related to Async Queries feature label Aug 10, 2026
@bito-code-review

bito-code-review Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

Bito Review Skipped - Source Branch Not Found

Bito didn’t review this change because the pull request is no longer valid. It may have been merged, or the source/target branch may no longer exist.

@netlify

netlify Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for superset-docs-preview ready!

Name Link
🔨 Latest commit d237f3d
🔍 Latest deploy log https://app.netlify.com/projects/superset-docs-preview/deploys/6abffb21c882a500093eede1
😎 Deploy Preview https://deploy-preview-43004--superset-docs-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
@codecov

codecov Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.28%. Comparing base (bc3698b) to head (0658907).
⚠️ Report is 46 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #43004      +/-   ##
==========================================
+ Coverage   82.22%   82.28%   +0.06%     
==========================================
  Files        2995     2995              
  Lines      184993   185098     +105     
  Branches    42818    42832      +14     
==========================================
+ Hits       152107   152307     +200     
+ Misses      30127    30031      -96     
- Partials     2759     2760       +1     
Flag Coverage Δ
hive 36.30% <ø> (-0.01%) ⬇️
javascript 77.88% <ø> (+<0.01%) ⬆️
mysql 55.32% <ø> (-0.02%) ⬇️
postgres 55.33% <ø> (-0.03%) ⬇️
presto 38.17% <ø> (-0.01%) ⬇️
python 86.24% <ø> (+0.11%) ⬆️
sqlite 55.06% <ø> (-0.02%) ⬇️
unit 79.23% <ø> (+0.14%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@drivaspreset drivaspreset changed the title add global async query playwright tests feat: add global async query playwright tests Aug 10, 2026
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
@rusackas

Copy link
Copy Markdown
Member

Heya @drivaspreset, nice coverage here on GAQ. @sadpandajoe's review comments are still open though, mostly pointing at duplicated code that could reuse existing helpers (apiPutChart, apiPostChart, the combo box filter component, the button component) - worth folding those in, this file's big enough that the reuse would help.

Codeant's race-condition threads look legit too: the girl/boy race assertion around line 583 doesn't actually confirm the fast request completed before checking for staleness, and the native-filter dropdown test around line 1172 arms its response listener before navigation, so it could pass without the click ever hitting GAQ. Worth tightening those up before merging.

@drivaspreset

Copy link
Copy Markdown
Contributor Author

Heya @drivaspreset, nice coverage here on GAQ. @sadpandajoe's review comments are still open though, mostly pointing at duplicated code that could reuse existing helpers (apiPutChart, apiPostChart, the combo box filter component, the button component) - worth folding those in, this file's big enough that the reuse would help.

Codeant's race-condition threads look legit too: the girl/boy race assertion around line 583 doesn't actually confirm the fast request completed before checking for staleness, and the native-filter dropdown test around line 1172 arms its response listener before navigation, so it could pass without the click ever hitting GAQ. Worth tightening those up before merging.

Thanks for the flag! Joe's comments are now folded in — apiPutChart/apiPostChart replace the raw calls, and the setup/response-listener duplication is extracted into helpers (setupDashboardWithBigNumberCharts, trackChartAsyncSignals/trackMultiChartAsyncSignals) in dashboard-test-helpers.ts. The combo-box and apply-button reuse now goes through the existing DashboardFilterBar/Button components instead of hand-rolled locators.

Codeant's two threads were legit — fixed both:

  • Girl/boy race assertion: the chart actually keeps showing the stale value the entire time a query is loading (confirmed via trace) rather than blanking, so the old assertion could pass without girl's second request ever completing. Reworked it to anchor on a fresh network-response tracker scoped to the race window instead of display text — which also surfaced that a repeated identical filter selection can hit GAQ's cache-hit shortcut (200, not 202); the fix accepts either as valid proof of completion.
  • Native-filter dropdown test: moved the GAQ-signal assertion to run before the dropdown is touched at all, so it's explicit in code (not just a comment) that the async fetch happens during filter-panel init, and opening the dropdown is a separate, decoupled render check.

Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/dashboard-test-helpers.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
Comment thread superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts Outdated
signals.sawFinalCachedFetch,
'once done, the client should fetch the real payload from /api/v1/chart/data/<cache_key>',
).toBe(true);
}).toPass({ timeout: TIMEOUT.CHART_RENDER });

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The required Playwright job currently times out here because the forced refresh never produces the expected 202; the same failure repeats in the resilience and multi-chart cases, so this PR leaves the required CI check red. Could we provision the GAQ flag/worker for this suite (or keep these specs out of the required matrix) before relying on these assertions?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Taking your second option: the GAQ specs now stand down via the existing
isFeatureEnabled helper when GLOBAL_ASYNC_QUERIES is off, so the required run
collects and skips them instead of timing out — the same pattern the
recently-archived specs use for SOFT_DELETE. The specs themselves are
unchanged, so they start running for real the moment a flag-on server exists.

Your first option is tracked in
https://app.shortcut.com/preset/story/113559: the flag via
GLOBAL_ASYNC_QUERIES

playwright-tests (chromium) and pre-commit are both passing now

@drivaspreset

Copy link
Copy Markdown
Contributor Author

Status update after merging master up — all threads addressed and CI is green.

Merge with master

#44659 ("collapse Playwright experimental workflow into E2E playwright-tests")
deleted .github/workflows/superset-playwright.yml, which is where the GAQ job
lived, and removed the INCLUDE_EXPERIMENTAL machinery from
playwright.config.ts and bashlib.sh.

playwright-tests-gaq therefore moved into superset-e2e.yml. I kept it as its
own job rather than folding it in as a step of playwright-tests, because it
needs a Celery worker and a 60s startup window — putting that on the required
path would let a GAQ flake block unrelated PRs. It stays continue-on-error
and outside playwright-tests-required, which still gates only on
playwright-tests.

Review fixes (c9dcafb)

  1. Did-the-suite-run gate now counts expected + unexpected + flaky as
    "executed" instead of expected alone, so a run where every test genuinely
    fails reports the real failure rather than blaming an inactive
    GLOBAL_ASYNC_QUERIES.

  2. Suite selection is now --project=chromium-gaq instead of a
    hand-maintained three-file list. playwright.config.ts's testMatch — the
    same glob that excludes these specs from the default and sqllab projects —
    is now the single definition of what the suite contains, so a new matching
    spec can't end up running nowhere.

  3. DISTRIBUTED_COORDINATION_CONFIG moved out of the shared
    superset_test_config into a new superset_test_config_gaq, following the
    existing _thumbnails / _sqllab_backend_persist_off pattern. It was
    leaking a real Redis backend into every unit-test run via conftest.py,
    because _init_distributed_coordination never clears
    _distributed_coordination. Only the GAQ job points at the new config.

  4. zizmor: the GAQ job's six ./.github/actions/cached-dependencies uses
    now carry the # zizmor: ignore[self-repository] suppression the other
    sixteen in the file already had.

Correction on the change-detector thread

The playwright token I added to the frontend pattern is no longer in the
branch. It existed so superset-playwright.yml would trigger its own jobs, and
that file no longer exists — GAQ now lives in superset-e2e.yml, which the
pre-existing e2e token already matches. I kept ^\.github/actions/ and its
test, since composite actions are still matched by nothing else.

CI

All checks pass, including both GAQ legs:

Running with no explicit paths (project selection comes from PLAYWRIGHT_EXTRA_ARGS, if set)
Running 10 tests using 1 worker
GAQ suite: 10 passed, 0 failed, 0 flaky, 0 skipped

0 flaky is the meaningful part: this suite previously reached green via a
retry after tag_name_key / Chart could not be created, so that confirms the
race window is closed rather than simply not hit.

Comment thread .github/workflows/superset-e2e.yml Outdated
GITHUB_TOKEN: ${{ github.token }}
services:
postgres:
image: postgres:17-alpine

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This job pulls postgres:17-alpine and redis:7-alpine (line 493) straight from Docker Hub, but the sibling playwright-tests job in this same file uses the GHCR mirror instead (ghcr.io/apache/superset/ci/postgres:17-alpine / .../redis:7-alpine) — that switch (#40882) was specifically to avoid Docker Hub's anonymous-pull rate limit hitting shared runner IPs. This job runs on every PR, not just merges, continue-on-error: true, and isn't part of the required check, so a rate-limit hit here fails both matrix legs at container init silently, with no signal to anyone. Should this use the same GHCR-mirrored images as the rest of the workflow?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — fixed in d56f007. Both services now use the GHCR mirrors, matching every other job in this file:

image: ghcr.io/apache/superset/ci/postgres:17-alpine
image: ghcr.io/apache/superset/ci/redis:7-alpine

Your point about the failure mode being invisible is the part that made this worth fixing rather than leaving: on a continue-on-error job outside the required check, a rate-limit hit at container init produces no signal to anyone, so the suite would silently stop providing coverage while the PR still looked green.

While in this job I also fixed two smaller inconsistencies against the sibling playwright-tests: the step comment still referred to playwright-tests-experimental (deleted by #44659), and "Set safe app root" interpolated ${{ matrix.app_root }} directly into the script where the sibling passes it via env:.

datasetName: options.datasetName,
datasetId: options.datasetId,
chartNamePrefix: options.namePrefix,
chartSpecs: [BIG_NUMBER_COUNT_SPEC],

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

setupDashboardWithSelectFilter() always builds its chart from BIG_NUMBER_COUNT_SPEC (the saved count metric), but its only caller with a virtual dataset — the filter-dropdown test in global-async-query.spec.ts — creates that dataset via apiPostVirtualDataset, which carries no saved metrics. The chart-data query for that dashboard would fail ("Metric 'count' does not exist"), and the test wouldn't catch it since it only asserts on the filter dropdown's async signals and options, never on the chart itself. Should this take an explicit chart spec (or an ad-hoc metric, like the cold-first-load test does) instead of hardcoding BIG_NUMBER_COUNT_SPEC?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right, and it was worse than "would fail" — it was failing, silently. I confirmed the mechanism: CreateDatasetCommand calls fetch_metadata, which only discovers columns and seeds no metrics, so a saved-metric reference against an API-created dataset raises Metric '%(metric)s' does not exist (superset/models/helpers.py:4748). That chart has been erroring on every run of this test, and because the test only ever looked at the filter dropdown, nothing caught it.

Fixed in d56f007:

  • setupDashboardWithSelectFilter now takes an optional chartSpec (default unchanged: BIG_NUMBER_COUNT_SPEC), and the doc on that constant now says plainly that its count is the saved metric and will not resolve on an API-created dataset.
  • The filter-dropdown test passes BIG_NUMBER_ADHOC_COUNT_SPEC — an ad-hoc COUNT(name), shared as ADHOC_COUNT_NAME_METRIC, which also replaces the inline copy the cold-first-load test had.
  • The test now asserts on the chart too, so this can't regress unnoticed: it renders a digit, has no .ant-alert-error, and completes its own 202 -> 200 round trip.

Green on the current run (test 9, both matrix legs).

for (const [index, chart] of charts.entries()) {
expect(
displayedValues[index],
`chart ${chart.id} (${chart.sliceName}) should show its own count (${expectedValues[index]}) after the refresh, not another chart's result`,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This compares each chart's post-refresh text to its own pre-refresh value, so it passes whether the refresh genuinely re-rendered fresh data or the DOM simply never updated at all — birth_names is static, so a correct refresh reproduces the same number as before. The signal-based block above already proves every chart completed its 202→200 network round trip; nothing here proves the DOM actually re-painted with that response. Could this assert against something that must change on a correct refresh, to actually prove the render happened?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed — as written that assertion could not distinguish a real re-render from a DOM that never updated, since birth_names is static and a correct refresh reproduces the same number.

Fixed in d56f007 by giving the test something that must change. The charts now sit on a per-run virtual dataset that stamps each query with the server clock:

SELECT name, CAST(EXTRACT(EPOCH FROM CURRENT_TIMESTAMP) * 1000 AS BIGINT) AS queried_at_ms FROM birth_names

A ninth chart shows MAX(queried_at_ms), and the refresh must make it strictly increase:

await expect
  .poll(readClock, { timeout: TIMEOUT.CHART_RENDER })
  .toBeGreaterThan(clockBefore);

That is the render-level proof the network block can't give: a stale DOM fails it. The chart carries y_axis_format: ',d' because the default SMART_NUMBER rounds two stamps seconds apart to the same 1.76T.

The eight per-name identity checks stay exactly as they were — with the repaint now established independently, "each chart still shows its own count" becomes a real anti-shuffling check rather than something that passes by default.

Passing on the current run (test 8, both legs).

await filterBar.selectOption('girl');
await filterBar.apply();
await expect(value).toHaveText(/\d/, { timeout: TIMEOUT.CHART_RENDER });
const expectedGirlText = await value.textContent();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This can capture the pre-filter value as expectedGirlText: the chart already shows a digit (the previous/unfiltered value) while girl's query is still in flight, and toHaveText(/\d/) — unlike the signal-based checks added later in this same test — doesn't wait for girl's request to actually resolve before the text is read. If girl's query is slow here, this baseline ends up wrong, and the race assertion below is then checked against it. Should this wait for a network signal (as the rest of the test does) before capturing the baseline?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct — and it's the same trap the later part of this test already documents: the chart keeps displaying the previous value while a query is in flight, so toHaveText(/\d/) is satisfied by the unfiltered total and the baseline silently becomes wrong whenever girl's query is slow.

Fixed in d56f007 by gating the baseline on the network, the way the race assertion below it already does:

const baselineSignals = trackGaqSignals(page);
await filterBar.selectOption('girl');
await filterBar.apply();
await expect(() => {
  const statuses = baselineSignals.submitStatusesFor(chartId);
  expect(statuses).not.toHaveLength(0);
  expect(statuses.every(s => s === 200 || s === 202)).toBe(true);
  expect(statuses[statuses.length - 1]).toBe(200);
}).toPass({ timeout: TIMEOUT.CHART_RENDER });

Ending on a 200 covers both legitimate shapes — a straight cache hit, or 202 then 200 — while rejecting a 4xx/5xx that would otherwise leave stale pixels on screen for the text read to pick up. Only then is expectedGirlText captured.

Passing on the current run (test 2, both legs).

*
* Failure and edge-case behavior lives in global-async-query-resilience.spec.ts.
* SQL Lab's smoke check lives in tests/sqllab/, which needs the
* `chromium-sqllab` project rather than this directory's default one.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This says the SQL Lab smoke check needs the chromium-sqllab project, but chromium-sqllab's testIgnore deliberately excludes it (see playwright.config.ts) — it only runs under chromium-gaq, same as these dashboard specs. A maintainer following this comment to run the smoke test with --project=chromium-sqllab would collect zero tests. Can this reference chromium-gaq instead?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right — the comment said the opposite of what the config does. Fixed in d56f007:

 * SQL Lab's smoke check lives in tests/sqllab/ but runs under the same
 * `chromium-gaq` project as these specs -- `chromium-sqllab` deliberately
 * excludes it via `testIgnore`, since it needs the flag only the GAQ job sets.

I also updated the header of global-async-query-sqllab.spec.ts itself, which described how that project gets selected in terms that predated the switch to --project=chromium-gaq.

Five review threads, plus what a pass over the same files turned up:

- superset-e2e.yml: the GAQ job pulled postgres:17-alpine and redis:7-alpine
  from Docker Hub while every other job in the file uses the GHCR mirrors
  (apache#40882). On a non-required, continue-on-error job a rate-limit hit would
  fail both legs at container init with no signal to anyone. Switched to the
  mirrors. Also: the step comment still named playwright-tests-experimental,
  deleted by apache#44659; and "Set safe app root" interpolated matrix.app_root
  into the script where the sibling job passes it through env.

- setupDashboardWithSelectFilter always built its chart from
  BIG_NUMBER_COUNT_SPEC, i.e. the saved `count` metric, but the filter-dropdown
  test hands it an API-created virtual dataset, and fetch_metadata seeds no
  metrics on those -- so that chart failed with "Metric 'count' does not
  exist" and the test could not see it, asserting only on the filter. The
  helper now takes a chartSpec; the test passes an ad-hoc COUNT(name) (shared
  as ADHOC_COUNT_NAME_METRIC / BIG_NUMBER_ADHOC_COUNT_SPEC, replacing the
  cold-first-load test's inline copy) and asserts the chart rendered a number,
  shows no error alert, and completed its own 202 -> 200 round trip.

- The many-charts refresh test compared each chart's post-refresh text to its
  own pre-refresh text. birth_names is static, so that passes whether the DOM
  repainted or never updated at all; the network block proves the round trips,
  not the render. The charts now sit on a per-run virtual dataset that stamps
  each query with CURRENT_TIMESTAMP in ms, and a ninth chart shows MAX of that
  stamp with y_axis_format ',d' (SMART_NUMBER would fold two stamps into the
  same "1.76T"). A forced refresh must make it strictly increase, which a DOM
  that never repainted cannot do. The eight per-name identity checks stay,
  now as a real correctness check rather than a tautology.

- The filter-race test read its "girl" baseline after toHaveText(/\d/), which
  the still-displayed unfiltered total satisfies while girl's query is in
  flight, so a slow query made the baseline wrong. It now waits for girl's
  chart-data round trip at the network level (200, or 202 then 200) before
  reading the value, as the race itself does.

- The dashboard spec header sent readers to chromium-sqllab for the SQL Lab
  smoke check, whose testIgnore deliberately excludes it; it runs under
  chromium-gaq. Fixed, and the sqllab header's description of how that
  project is selected updated to match --project.

- constants.ts: the GAQ block had been inserted between EMBEDDED's docblock
  and EMBEDDED itself. Moved above the docblock.

- Dropped the DistributedLock mocks added to oauth2_tests.py and
  screenshot_test.py. They papered over the shared test config leaking a Redis
  coordination backend into unit tests; that config is now scoped to the GAQ
  job (c9dcafb), so the mocks' stated rationale no longer holds and the
  files return to master.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
expect(
[200, 202],
'"girl"\'s fast chart-data submission should have succeeded (200 cache-hit or 202 async-accepted)',
).toContain(signals.submitStatusFor(chartId));

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On a loaded CI runner this can pass without actually proving a race. submitStatusFor(chartId) returns whichever chart-data response arrives first for this slice, not specifically "girl"'s -- "boy"'s request only reaches the server once its route-intercepted delay elapses, and that delay starts as soon as boy is applied, before girl's own select/apply cycle even runs. If that UI cycle plus network latency eats more than the 500ms margin left over from RACE_DELAY_MS, boy's response can land inside this window and satisfy the check instead of girl's, so the race this asserts isn't reliably what gets observed. Could this correlate the response with the filter that produced it (e.g. the request params) instead of relying on first-response ordering?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, and it's worse than the window being tight — the check could pass on boy's response outright. submitStatusFor(chartId) keys only on slice id, and both requests are for that slice, so it returns whichever landed first.

The arithmetic: boy unparks at boyApplied + 3000, while the window ran from girlApplied for 3000 - 500. Boy lands inside it whenever girl's select/apply cycle exceeds 500ms — easy on a loaded runner — and the test goes green without girl ever completing.

Fixed in 686ba1e by correlating on the payload, as you suggested. A dashboard merges its native filters in as { col, op: 'IN', val: [...] } clauses (getSelectExtraFormData, src/filters/utils.ts), so the request identifies itself:

const statusesFor = (value: string) =>
  signals.submitStatusesWhere(chartId, body =>
    nativeFilterValuesIn(body, FILTER_COLUMN).includes(value),
  );

trackGaqSignals now keeps each chart-data request body alongside its status and exposes submitStatusesWhere; nativeFilterValuesIn reads those clauses back. submitStatusesFor is unchanged, so no other caller is affected.

Two supporting changes, about the window rather than the correlation:

  • It's now measured — RACE_DELAY_MS - (Date.now() - boyAppliedAt) — rather than a hard-coded RACE_DELAY_MS - 500 counted from the wrong event, so it cannot silently shrink to nothing, and the test fails loudly if girl was applied after boy's delay had already elapsed.
  • RACE_DELAY_MS 3000 -> 8000, so that UI cycle plus latency has room.

The assertion also now requires boy to still be parked while girl completes, so a run where the delay failed to hold boy back reports itself instead of quietly testing nothing.

Passing on the current run (test 2, both matrix legs, 0 flaky).

…arrival order

`submitStatusFor(chartId)` returns the first status recorded for a slice, and
both requests in the race are for the same slice. "boy"'s route delay starts
when boy is applied -- before girl's own select/apply cycle runs -- so on a
loaded runner boy's response can land inside the assertion window and satisfy
the check while girl never completed. The test would pass without the race it
claims to prove.

The payload already carries the answer: a dashboard merges its native filters
in as `{ col, op: 'IN', val: [...] }` clauses (`getSelectExtraFormData`, in
src/filters/utils.ts). `trackGaqSignals` now keeps each chart-data request body
alongside its status and exposes `submitStatusesWhere(sliceId, matches)`, and
`nativeFilterValuesIn(body, column)` reads those clauses back, so the test can
name the request it means. `submitStatusesFor` is unchanged for every existing
caller.

Two supporting changes, both about the window rather than the correlation:

- The window was hard-coded `RACE_DELAY_MS - 500`, measured from girl's apply
  though the delay starts at boy's. It is now the delay minus the time the UI
  cycle actually took, so it cannot silently shrink to nothing, and the test
  fails loudly if girl was applied after boy's delay had already elapsed.

- RACE_DELAY_MS 3000 -> 8000, so that cycle plus network latency has room.

The assertion also now requires boy to still be parked while girl completes: a
run where the delay failed to hold boy back is reported as such instead of
quietly testing nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

// Give the superseded "boy" response every chance to arrive and clobber it.
await page.waitForTimeout(RACE_DELAY_MS + 2000);
await expect(value).toHaveText(raceResultText ?? '');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This final wait can't actually prove the anti-clobber behavior it's testing. When "girl" is applied, the app aborts the in-flight "boy" request client-side (chartAction.ts's setTimeout(() => prevController.abort(), 0), fired as soon as the new query starts) rather than letting it run to completion and discarding a late response. That abort happens almost immediately, well before this route's artificial RACE_DELAY_MS delay would release "boy"'s response -- so the browser cancels that request outright, and no late "boy" response is ever possible through this path for the code below to wait out. The waitForTimeout(RACE_DELAY_MS + 2000) + re-assert would pass the same way whether or not the app's supersession logic is correct.

Could the route handler hold "boy" open without letting the click complete (e.g. delay before route.continue() on the first interception, keeping the request itself in flight rather than resolved-then-aborted), or is there another way to get a genuine late response into this window?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right, and thanks for chasing it to chartAction.ts — I confirmed the abort at line 813:

setTimeout(() => prevController.abort(), 0);

So the browser cancels "boy" as soon as "girl"'s query starts, long before the route delay would release anything. No late response is reachable through this path, which makes both the final waitForTimeout + re-assert and the statusesFor('boy') emptiness check I added vacuous — they pass whether or not supersession works.

Fixed in 50d2bf7 by asserting the mechanism that actually protects the screen: the cancellation itself.

expect(
  boyCancelled,
  '"boy" should have been cancelled client-side when "girl" superseded it',
).toBe(true);

boyCancelled is set from either signal, since which one fires depends on when the abort lands relative to the parked route: page.on('requestfailed') for the aborted request, or the route.continue() rejection that follows an already-aborted one (previously an unhandled rejection, now caught — that rejection is the expected path here, not a failure).

I kept the wait rather than deleting it, but for a narrower, honest reason now stated in the comment: it is the window a regressed cancellation would let a stale result land in, with "boy" asserted to have produced no response at all.

I could not verify locally which of the two signals fires — this stack can't run the suite — so it mattered that CI exercised it: test 2 passes on both matrix legs, 10 passed, 0 flaky.


await filterBar.selectOption('boy');
await filterBar.apply();
const boyAppliedAt = Date.now();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

boyAppliedAt is captured after filterBar.apply()'s UI promise resolves, not when the intercepted request actually starts the RACE_DELAY_MS timer in the route handler above. If that UI cycle is slow on a loaded runner, remainingParkMs (line 233) overstates how much of the delay is actually left, and the statusesFor('boy')).toHaveLength(0) check at line 268 can fail on a perfectly healthy run because "boy" is legitimately released before the computed deadline. Could the delay's start be measured from the route interception itself (e.g. a timestamp set inside the page.route handler) rather than from the client-side apply() return?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct — and the consequence was worse than an overstated deadline: statusesFor('boy').toHaveLength(0) could fail on a perfectly healthy run, exactly as you describe.

Fixed in 50d2bf7. The timestamp is now stamped where the delay actually starts, inside the route handler:

await page.route(raceRoute, async route => {
  matchCount += 1;
  const isBoy = matchCount === 1;
  if (isBoy) {
    boyParkedAt = Date.now();
    await new Promise(resolve => { setTimeout(resolve, RACE_DELAY_MS); });
  }
  ...

boyAppliedAt and the derived remainingParkMs are gone; every remaining use measures from boyParkedAt. The brittle check you flagged is gone too — per the thread above, the test now asserts the cancellation rather than "boy" having produced no response within a computed window.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This can still fail a healthy run: girl may start at 1s and correctly cancel boy, but a response at 9s makes the 8s assertion fail because the deadline is checked after the response wait. Could this compare girl's request-start time with boyParkedAt instead?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right again — the deadline was checked after the block that waits for girl's response, so Date.now() there was response-arrival time rather than when girl's request started. Your 1s/9s case fails a run that did exactly the right thing.

Fixed in e9205bd. Both moments are stamped at interception and compared stamp to stamp, so response latency no longer enters it:

expect(
  girlRequestedAt - boyParkedAt,
  '"girl" should have started while "boy" was still parked',
).toBeLessThan(RACE_DELAY_MS);

The route handler also picks its request by payload rather than arrival order now, consistent with how the rest of the test tells the two apart, so matchCount is gone. The only surviving Date.now() is inside a waitForTimeout floored at Math.max(..., 0), so it cannot fail a run.

Since this was the third round on this test, I went back over the whole thing rather than just the reported line, and found something worse in 1ba7472:

the test could not detect the clobber it is named after. The baseline applied "girl", and applying "boy" parks its request while the chart keeps rendering its previous value — so the screen showed girl's number from the baseline onward and toHaveText(expectedGirlText) was already true before the race began. It still worked as a clobber detector, since a stale "boy" result would change the number, but nothing established that "boy" and "girl" render different numbers. Had they matched, a clobber would have been invisible and every assertion would still have passed. The multi-chart test guards this explicitly; this one did not.

Both counts are now read up front through the same payload-correlated round-trip wait, and asserted to differ before the race runs:

expect(
  girlText,
  '"boy" and "girl" should render different counts, or a clobber would be invisible',
).not.toBe(boyText);

The final check is then a real invariance check — still "girl", and necessarily not "boy" — with the mechanism (cancellation, and "boy" having produced no response) asserted separately rather than one standing in for the other. Also dropped raceResultText, which was captured right after asserting the value equalled expectedGirlText and so could only ever hold that same string.

Green on both matrix legs, 10 passed, 0 failed, 0 flaky, 0 skipped.

);
const [chart] = charts;
const [value] = valueLocators;
const errorAlert = dashboard.getChart(chart.id).locator('.ant-alert-error');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

errorAlert is the same locator before and after forceRefresh(), and the refreshed metric is identical to the one that already failed on initial load -- so the checks at lines 100-102 (visible, "Data error", BAD_COLUMN) would pass identically whether the refresh's own query ever completed or the DOM simply never changed. Only the signals check at lines 104-113 (202 + a status-changes poll) proves a fresh submission happened, and even that only proves the task was queued and polled, not that its failure is what's actually rendered. Would asserting on something that changes across the refresh (e.g. a fresh task id in the poll response, or clearing/re-showing the alert element around the forceRefresh() call) close that gap?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed on both halves: the alert is already on screen from the initial load, and the refresh re-runs the identical broken query, so those three assertions hold up whether the refresh completed or the DOM never changed.

Fixed in 50d2bf7 by requiring the failure to come back over the wire on the refresh's own traffic, before the alert is looked at:

expect(
  responseBodies.filter(body => body.includes(BAD_COLUMN)),
  "the refresh's own chart-data response should carry the failure, rather than the alert being left over from the initial load",
).not.toHaveLength(0);

responseBodies is captured from a listener attached alongside trackGaqSignals, i.e. after the initial load has settled, so only the refresh's responses can satisfy it. That is stronger than the fresh-task-id option you suggested: it is not just that a new task was queued and polled, but that the rendered failure is the one this cycle produced.

The alert assertions still run, moved below so they read as confirming the rendering rather than carrying the proof.


/**
* Global Async Queries (GAQ) under stress: a query that fails, a superseded
* query racing a newer one, a lost channel token, and a page torn down

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This header says the file covers "a lost channel token" scenario, but none of the four tests below exercises losing the async-token cookie (that case is described in the PR body as living elsewhere). Also, the comment at lines 213-215 ("any chart-data response seen inside the race window belongs to 'girl'") is stale against the code that follows it: lines 240-243 and 265-268 specifically handle the case where "boy"'s response can also land in that window, via payload-correlated statusesFor rather than raw arrival order. Worth trimming the header to what this file actually covers, and updating/removing the now-inaccurate "belongs to girl" line?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both correct. Fixed in 50d2bf7 — the header now names what the four tests here actually cover:

 * Global Async Queries (GAQ) under stress: a query that fails, a superseded
 * query racing a newer one, a programmatic request that must stay synchronous,
 * and a page torn down mid-flight.

The "belongs to 'girl'" line is gone; it had been true of the original arrival-order check and stopped being true the moment the payload-correlated statusesFor landed. Both strings are now at zero occurrences in the file.

While here I also cut the comment blocks that had drifted into restating the code rather than explaining it, across this file, dashboard-test-helpers.ts and the SQL Lab spec (comment lines 100 -> 92, 242 -> 220, 43 -> 34).

# setup-backend, change-detector). A change to the setup they share can
# break those jobs while touching nothing under superset-frontend/, so
# it has to reach them.
r"^\.github/actions/",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This .github/actions/ pattern (and its own comment, which says these composite actions are "every Playwright job's" shared setup, explicitly including setup-backend) is added only under "frontend", not "python". setup-backend is a plain backend/Python setup action, not a frontend one -- a PR that changes only .github/actions/setup-backend/ would set frontend=true but leave python=false, so the Python unit/integration jobs gated on that output would skip re-running despite their own setup changing. Should this pattern (or at least the setup-backend/change-detector actions) also be added under "python"?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — setup-backend is a backend action, and gating it on "frontend" alone meant a PR touching only .github/actions/setup-backend/ set frontend=true, python=false, and skipped the Python jobs whose own setup had changed.

Fixed in 50d2bf7: the pattern is now in both groups, and the comment no longer claims these are only the Playwright jobs' setup.

.github/actions/setup-backend/action.yml  -> python=True  frontend=True
.github/actions/cached-dependencies       -> python=True  frontend=True

The test is parametrized over both groups rather than asserting only frontend, so the same gap can't reopen on one side:

@pytest.mark.parametrize("group", ["frontend", "python"])
def test_composite_action_changes_trigger_tests(group: str) -> None:

Five review threads on the resilience spec and the change detector.

- The race test's final wait could not prove anti-clobber. Supersession is
  implemented by cancelling the old request (chartAction.ts aborts the previous
  controller as soon as the new query starts), so "boy" is aborted long before
  its route delay would release a response -- no late response is reachable
  through this path, and `waitForTimeout` + re-assert passed either way. The
  test now asserts the cancellation itself, and keeps the wait for what it is
  really worth: the window a regressed cancellation would let a stale result
  land in, with "boy" asserted to have produced no response at all.

- The park deadline was measured from `apply()`'s return, not from interception,
  so a slow UI cycle overstated the time left and could fail the "boy still
  parked" check on a healthy run. It is now stamped inside the route handler.
  Continuing an already-aborted request rejects, which is the expected path
  here, so that rejection is caught rather than surfacing as an error.

- The broken-chart test re-ran the identical failing query, so the alert
  assertions passed whether the refresh completed or the DOM never changed. It
  now requires the failure to come back over the wire on the refresh's own
  chart-data response before looking at the alert.

- The file header advertised a lost-channel-token case this file does not
  cover, and a comment claimed any response in the race window belongs to
  "girl" -- untrue since the payload-correlated lookup landed. Both corrected.

- change_detector: `^\.github/actions/` was only under "frontend", so a PR
  touching just setup-backend set frontend=true and python=false and skipped
  the Python jobs whose own setup changed. Added under "python" too, and the
  test now covers both groups.

Also trimmed the longest comment blocks across these files, which had grown to
restating the code rather than explaining it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@drivaspreset
drivaspreset force-pushed the test-global-async-query-playwright branch from b978b20 to 50d2bf7 Compare October 1, 2026 17:34
drivaspreset and others added 4 commits October 1, 2026 11:52
oxlint's no-void rejected `void response.text().then(...)`, failing
lint-frontend and pre-commit. An async response handler with try/catch reads
better anyway, and makes explicit why a failure is ignored: a superseded
request's body is no longer retrievable.

Verified with oxlint 1.83.0 (the lockfile version) and oxfmt 0.68.0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Grouping the review feedback on this PR, one theme accounts for most of it:
assertions that hold whether or not the behaviour under test happened. Four
shapes recurred -- asserting state that was already true before the action;
not identifying which of several in-flight requests is being asserted;
asserting something the implementation makes unreachable; and leaving a
component that can fail silently unasserted.

Each was reported and fixed one site at a time. This applies the same audit to
the sites that were not reported yet.

- The forced-refresh test asserted the chart was visible and showed a digit
  after refreshing -- both already true beforehand, on static data that
  reproduces the same number. It is the same defect reported for the
  many-charts test. Its chart now renders the query clock, so the refresh must
  advance a value that cannot advance on its own.

- The cache-hit reload asserted only "a digit" after reloading. A cache hit
  has to reproduce the cached result, so it now asserts that exact value.

- Same for the navigate-away test: returning must show the value it had before
  leaving, not merely some number.

The query-clock dataset and its chart spec were inline in the many-charts test;
they are now shared helpers (createQueryClockDataset,
BIG_NUMBER_QUERY_CLOCK_SPEC, readQueryClock) used by both tests, which also
answers the earlier review theme about duplicating fixture setup.

Audited the four remaining `toHaveText(/\d/)` uses: two capture a baseline for
a later exact-value assertion, one proves a cold first load rendered from
nothing, one proves recovery from an error alert to a value. All are assertions
that can fail, so they stay.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
apache#44829 removed the Cypress infrastructure, deleting cypress-matrix and
cypress-matrix-required from superset-e2e.yml. This branch's
playwright-tests-gaq job sits between the two deleted jobs, so the whole span
conflicted.

Took the deletion and kept the GAQ job. Two follow-ons that fall out of it:

- The GAQ job's checkout comment pointed at "the Cypress workflow", which no
  longer exists; master reworded the same comment in playwright-tests, so this
  now matches.

- The required-status-check anchor comment used to introduce both *-required
  jobs. With cypress-matrix-required gone it was left documenting
  playwright-tests-required from above the GAQ job. Moved the GAQ job ahead of
  it so each comment adjoins the job it describes.

Verified: no Cypress references remain in the file, the required gate still
needs only [changes, playwright-tests] so GAQ stays non-blocking, and all six
cached-dependencies uses keep their zizmor suppression.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the requires:rebase Requires rebasing on top of current master label Oct 2, 2026
drivaspreset and others added 3 commits October 2, 2026 12:42
The branch was 13 commits behind master. apache#44895 (classify changed files by
language, not directory) appended seven tests to change_detector_test.py, at
the same end-of-file position as this branch's composite-action test.

Kept both: upstream's block in place, this branch's test appended after it, so
the branch reads as a clean trailing addition. scripts/change_detector.py
auto-merged -- upstream's detect_languages/GROUP_LANGUAGE_EXTENSIONS and this
branch's `^\.github/actions/` pattern are independent.

Verified: 18 test functions (master's 17 plus this branch's one), all seven of
upstream's present, 19 cases pass, ruff clean, and the diff against master is
the 12 files this PR owns.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The "boy was still parked" check ran after the block that waits for girl's
response, so `Date.now()` there was response-arrival time rather than when
girl's request started. A healthy race with a slow response -- girl starting
at 1s, responding at 9s, against an 8s park -- failed the assertion.

Both moments are now stamped at interception and compared stamp to stamp:
girlRequestedAt - boyParkedAt < RACE_DELAY_MS. Response latency no longer
enters the comparison.

The route handler also picks its request by payload rather than arrival order,
consistent with how the rest of the test tells the two apart, so matchCount is
gone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Reviewing the test as a whole rather than the line last reported: the screen
showed "girl" from the baseline onward and never changed. Applying "boy" parks
its request, and the chart keeps rendering its previous value while a query is
in flight, so `toHaveText(expectedGirlText)` was already true before the race
began.

It was still a clobber detector -- a stale "boy" result would change the number
-- but nothing established that "boy" and "girl" render different numbers. Had
they matched, a clobber would have been invisible and every assertion would
still have passed. The multi-chart test guards this explicitly; this one did
not.

Both counts are now read up front, through the same payload-correlated
round-trip wait, and asserted to differ before the race runs. The final check
is then a real invariance check: still "girl", and necessarily not "boy".

Also dropped `raceResultText`, which was captured immediately after asserting
the value equalled `expectedGirlText` and so could only ever hold that same
string.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot removed the requires:rebase Requires rebasing on top of current master label Oct 2, 2026
@drivaspreset

Copy link
Copy Markdown
Contributor Author

@sadpandajoe — before you re-review, a note on something I did between rounds, so you aren't re-deriving it.

Rather than keep fixing reported lines one at a time, I went back over all of your review comments on this PR and grouped them. They fall into four themes, and one of them is 11 of the last 12:

Theme Status
Reuse / DRY — use the existing API helpers, extract duplicated fixture setup, split the file resolved
CI plumbing — required matrix, if: success(), change detector, zizmor, GHCR mirrors, shared test config resolved
Assertions that cannot fail the recurring one
Comments that contradict the code resolved

The third theme is one defect in four shapes:

  1. Asserting state that was already true before the action — the multi-chart text comparison; errorAlert before and after forceRefresh(); the pre-filter expectedGirlText baseline.
  2. Not identifying which of several in-flight requests is being asserted — submitStatusFor returning whichever responded first; toBeDefined() accepting a 4xx.
  3. Asserting something the implementation makes unreachable — the anti-clobber wait, since chartAction.ts aborts the superseded request.
  4. Leaving a component that can fail silently unasserted — the chart in the filter-dropdown test, which had been erroring on every run unnoticed.

So I audited every test in the suite for the same shapes instead of waiting for the next report. Three sites had it and were not yet reported:

  • forced dashboard refresh goes through the GAQ 202 -> poll -> done cycle — asserted the chart was visible and showed a digit after refreshing. Both were already true beforehand, on static data that reproduces the same number: the same defect you reported for the multi-chart test. Its chart now renders the query clock, so the refresh has to advance a value that cannot advance on its own.
  • reloading an already-cached dashboard... — asserted only "a digit" after reloading. A cache hit has to reproduce the cached result, so it now asserts that exact value.
  • navigating away mid-load and back... — same: returning must show the value it had before leaving, not merely some number.

The query-clock dataset and chart spec were inline in the multi-chart test; they are now shared helpers (createQueryClockDataset, BIG_NUMBER_QUERY_CLOCK_SPEC, readQueryClock) used by both, rather than duplicating fixture setup the way the August comments called out.

I also audited the four surviving toHaveText(/\d/) uses and deliberately kept them: two capture a baseline for a later exact-value assertion, one proves a cold first load rendered from nothing, and one proves recovery from an error alert to a value. All can fail.

Everything above is green — 80 checks, and the suite reports 10 passed, 0 failed, 0 flaky, 0 skipped on both matrix legs.

FILTER_COLUMN,
);
const isBoy = filterValues.includes('boy');
if (isBoy && boyParkedAt === 0) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Parking boy before its POST reaches Superset only tests cancellation of the submission, so dropping the AbortSignal forwarded to waitForAsyncData would leave accepted, superseded jobs polling/running without failing this test. Could we also switch filters after boy returns 202 and assert cancellation of its task IDs, or cover that signal forwarding at the chartAction boundary?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're right, and this one was a coverage gap rather than a weak assertion — thanks for pushing on it.

Supersession has two halves, and the test only covered the first. chartAction.ts forwards its abort signal into the wait:

// The optional signal lets a caller abort the wait (Stop pressed, chart
// superseded or unmounted), cancelling the outstanding tasks.
return waitForAsyncData(json as AsyncJob, refetch, signal);

and asyncEvent.ts is what turns that into actual cancellation:

waiter.onAbort = () => {
  unregister(waiter);
  cancelUnwaitedTasks(taskIds, submitTabId);   // -> POST /api/v1/task/<id>/cancel
  reject(new DOMException('Aborted', 'AbortError'));
};

Parking "boy" before its POST reaches Superset means it never reaches 202, so waitForAsyncData is never entered and none of that runs. Dropping the signal argument would leave accepted, superseded jobs polling and running with nobody waiting, and the test would stay green — exactly as you describe.

Added the other half in 0658907, as a second test rather than changing the existing one, since cancelling the submission is also a real path worth keeping:

  • A per-run cache-cold dataset, so "boy" is guaranteed to be accepted (202) rather than served synchronously from a warm cache.
  • The task-status poll is stalled rather than the submission. "boy" is accepted normally, but the client cannot observe its tasks finishing, so its waiter is still registered when "girl" aborts it. Without that the tasks could complete first and leave nothing to cancel — the test would pass while asserting nothing.
  • The assertion is on the cancel calls for "boy"'s own task ids, read out of its 202 response:
await expect
  .poll(() => cancelledTaskIds, { ... })
  .toEqual(expect.arrayContaining(boyTaskIds));

I took your first suggestion over the second deliberately: asserting the /cancel calls tests the observable consequence, so it still holds if the signal-forwarding is ever refactored, whereas asserting at the chartAction boundary would pin the current wiring.

Suite is 11 tests now. Both matrix legs pass on this commit.

The filter-race test parks "boy" before its POST reaches the server, so it only
covers cancelling the submission. Supersession has a second half: once a
submission is accepted, the client holds a waiter for its task ids, and
chartAction forwards its abort signal into waitForAsyncData, whose onAbort
calls cancelUnwaitedTasks -> POST /api/v1/task/<id>/cancel.

Drop that forwarding and superseded jobs keep polling and running server-side
with nobody waiting on them. The existing test cannot see it, because "boy"
never reaches 202 there.

This adds the other half. A per-run dataset keeps the cache cold so "boy" is
accepted rather than served from a warm cache, and the task-status poll is
stalled rather than the submission -- "boy" is accepted normally but the client
cannot observe its tasks finishing, so its waiter is still registered when
"girl" aborts it. The assertion is on the cancel calls for "boy"'s own task
ids, read from its 202.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@bito-code-review

bito-code-review Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #2bcbf3

Actionable Suggestions - 0
Additional Suggestions - 3
  • superset-frontend/playwright/tests/dashboard/dashboard-test-helpers.ts - 2
    • NaN on missing text · Line 767-767
      `Locator.textContent()` resolves to `string | null`; on `null`, `null?.replace(...)` yields `undefined` and `Number(undefined)` returns `NaN`, so `readQueryClock` can return `NaN` when the element detaches mid-`expect.poll` (see `global-async-query.spec.ts` polls). Assertions then fail as 'NaN to be greater than...' instead of a real cause. Throw on null text before converting. ([CWE-20](https://cwe.mitre.org/data/definitions/20.html))
    • Dialect-locked SQL stamp · Line 761-762
      `EXTRACT(EPOCH FROM CURRENT_TIMESTAMP)` is PostgreSQL/Oracle syntax; on SQLite or MySQL examples backends the dataset query would fail at execution. The repo does not pin the `examples` database backend for the Playwright environment, so this looks backend-dependent. If PostgreSQL-only is guaranteed, documenting that constraint in the docblock would make it explicit.
  • superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts - 1
    • Nullish fallback weakens assertion · Line 225-225
      `value.textContent()` is typed `string | null`, so `cachedText ?? ''` turns a failed capture into an assertion that the reloaded chart is empty — a vacuous pass with a misleading message instead of a clear one. Line 212's `toHaveText(/\d/)` makes null unlikely today, but the fallback still degrades diagnostics if the DOM changes; assert the capture explicitly before using it.
Filtered by Review Rules

Bito filtered these suggestions based on rules created automatically for your feedback. Manage rules.

  • scripts/change_detector.py - 1
Review Details
  • Files reviewed - 9 · Commit Range: f5ffe36..0658907
    • superset-frontend/playwright/tests/dashboard/dashboard-test-helpers.ts
    • superset-frontend/playwright/tests/dashboard/global-async-query-resilience.spec.ts
    • superset-frontend/playwright/tests/dashboard/global-async-query.spec.ts
    • superset-frontend/playwright/tests/sqllab/global-async-query-sqllab.spec.ts
    • superset-frontend/playwright/utils/constants.ts
    • tests/unit_tests/utils/oauth2_tests.py
    • tests/unit_tests/utils/screenshot_test.py
    • scripts/change_detector.py
    • tests/unit_tests/scripts/change_detector_test.py
  • Files skipped - 1
    • .github/workflows/superset-e2e.yml - Reason: Filter setting
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • Eslint (Linter) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@sadpandajoe
sadpandajoe merged commit a5ffac5 into apache:master Oct 6, 2026
81 checks passed
@sadpandajoe
sadpandajoe deleted the test-global-async-query-playwright branch October 6, 2026 19:03
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* fix(echarts): fix sparse sub-daily bar sizing and x-axis mislabeling (apache#44628)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mysql): require TLS when SSL is requested (apache#44723)

* fix(dynamodb): render time bounds as ISO 8601 so sub-day ranges match stored timestamps (apache#44702)

* fix(opensearch): page drill-to-detail samples with the OpenSearch SQL response format (apache#44703)

* fix(gsheets): pass the OAuth2 token and delegation subject through connect_args (apache#44709)

* fix(databricks): stop the string-type patch writing SQLAlchemy's shared colspecs (apache#44707)

* fix(oracle): map Oracle NUMBER, BINARY_FLOAT/DOUBLE and CLOB column types (apache#44685)

Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>

* chore(deps): bump undici from 7.29.0 to 7.30.0 in /superset-frontend in the security group across 1 directory (apache#44809)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* chore(deps): bump react-window from 2.3.2 to 2.3.3 in /superset-frontend (apache#44820)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(datafusion): render temporal SQL that DataFusion accepts (apache#44700)

* fix(db2): set current_schema to the catalog name of the selected schema (apache#44706)

* chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /superset-frontend/cypress-base (apache#44813)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* perf(security): memoise the user subject lookup within a request (apache#44017)

Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: shaurya <shauryajaiswal.dev@gmail.com>
Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

* fix(semantic-layer): honor provider preferred time dimension (apache#44997)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* feat(dashboard): add column allowlist to Group By native filter (apache#43736)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(soft-delete): preserve a shared datasource permission on purge (apache#45034)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* perf(versioning): defer capture policy until versioned work (apache#44928)

* fix(date-parser): reject malformed time ranges instead of scanning everything (apache#45098)

* chore(deps-dev): bump wait-on from 9.4.0 to 9.5.1 in /superset-frontend (apache#45048)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps): bump mapbox-gl from 3.31.0 to 3.32.0 in /superset-frontend (apache#45049)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-embedded-sdk (apache#45074)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the swc group across 2 directories with 1 update (apache#45118)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node in /superset-embedded-sdk (apache#45121)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump swagger-ui-react from 5.33.0 to 5.33.1 in /docs (apache#45122)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump yargs from 18.1.0 to 18.2.0 in /superset-frontend (apache#45129)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt in /docs (apache#45119)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code global:async-query Related to Async Queries feature risk:ci-script PR modifies scripts that execute in CI (supply chain risk) size/XXL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants