Skip to content

fix(sqllab): preserve exact decimals in results and exports - #44739

Merged
rusackas merged 17 commits into
apache:masterfrom
aminghadersohi:fix-sqllab-exact-decimals
Oct 1, 2026
Merged

rusackas merged 17 commits into
apache:masterfrom
aminghadersohi:fix-sqllab-exact-decimals

Conversation

@aminghadersohi

@aminghadersohi aminghadersohi commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

SUMMARY

SQL Lab sends Decimal values as JSON numbers. Even when the JSON contains all digits, JavaScript rounds them; reading the JSON result cache also loses precision before CSV export.

Convert decimals to exact fixed-point strings (format(value, "f"), so DECIMAL(38,18) zeros stay 0.000000000000000000 rather than 0E-18) at the SQL Lab record boundary, shared by synchronous results, JSON cache writes and Arrow-cache reads. Columns PyArrow cannot type as decimal (Decimal NaN/Infinity, or Decimals mixed with floats) are stringified the same way, with NaN and Infinity returned as null. Keep the DataFrame and shared chart JSON serializer numeric. Sort decimal strings by sign, decimal order and significand rather than parseFloat, including values differing only in their 38th digit. The grid comparator orders by type first (numbers, including exact decimal strings and infinities, then text, then NaN, then nulls), so mixed columns sort the same regardless of input order. Two plain numbers are compared directly, and parsed sort keys are cached per value. API behavior, including strings for numeric columns in sqlLab.onDidQuerySuccess extension listeners, is documented in UPDATING and the user guide.

BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF

Before: 12345678901234567890.123456789012345678 is a JSON number and rounds in the browser. After: the response contains the exact quoted value; the grid displays it and sorts it numerically. A component test clicks the column header and checks both directions.

TESTING INSTRUCTIONS

  • Backend dataframe tests: 39 pass after merging master, including high-scale zero and small-negative cases and a CSV export check that -0.000000100000000000 is not formula-escaped.

  • FilterableTable/component/comparator Jest tests: 67 pass locally. Six new comparator tests (type-first ordering, the [9, '5x', 10] permutations and a brute-force transitivity/antisymmetry check over mixed values) fail with the previous comparator. The parser-equivalence check agrees with the reference regex on all 111,111 enumerated inputs.

  • Result-set tests: 24 pass, including [Decimal('Infinity'), Decimal('-0.00000010')], Decimal NaN and a Decimal/float mix, with a CSV export check. The three new cases fail before the stringify_values change.

  • Sort benchmark (Node 22, 100k rows, median of 5 runs):

    Column master before this revision after
    plain numbers 30 ms 925 ms 32 ms
    decimal strings 500 ms 1294 ms 226 ms
    text 102 ms 467 ms 140 ms
  • Live PostgreSQL 17 and Databricks: exact DECIMAL(38,18) through SQL Lab HTTP, sync execution, JSON and Arrow caches, CSV exports; live chart SUM stays numeric. The upstream implementation was run separately without a serialization carry.

  • Pre-commit checks pass on the changed files, including the frontend type check. No dependency or lockfile changes.

To reproduce manually, execute SELECT CAST('12345678901234567890.123456789012345678' AS DECIMAL(38,18)) AS exact in SQL Lab, inspect the JSON response, sort nearby decimal values and export CSV. Re-run old cached queries after upgrading workers.

ADDITIONAL INFORMATION

  • Has associated issue:
  • Required feature flags:
  • Changes UI
  • Includes DB Migration
  • Introduces new feature or API: decimal response values become strings
  • Removes existing feature or API

@github-actions github-actions Bot added the doc Namespace | Anything related to documentation label Sep 28, 2026
@netlify

netlify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for superset-docs-preview ready!

Name Link
🔨 Latest commit 8f54a98
🔍 Latest deploy log https://app.netlify.com/projects/superset-docs-preview/deploys/6abd7a74219dcc00097819c1
😎 Deploy Preview https://deploy-preview-44739--superset-docs-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.67%. Comparing base (16271bb) to head (e1fb34c).
⚠️ Report is 23 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #44739      +/-   ##
==========================================
+ Coverage   81.58%   81.67%   +0.08%     
==========================================
  Files        2977     2978       +1     
  Lines      180822   181348     +526     
  Branches    41849    41921      +72     
==========================================
+ Hits       147531   148117     +586     
+ Misses      30568    30508      -60     
  Partials     2723     2723              
Flag Coverage Δ
hive 36.67% <33.33%> (+0.01%) ⬆️
javascript 77.08% <100.00%> (+0.02%) ⬆️
mysql 55.85% <48.71%> (-0.06%) ⬇️
postgres 55.85% <48.71%> (-0.07%) ⬇️
presto 38.59% <35.89%> (+<0.01%) ⬆️
python 85.86% <100.00%> (+0.13%) ⬆️
sqlite 55.58% <48.71%> (-0.07%) ⬇️
unit 78.70% <97.43%> (+0.18%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread superset-frontend/src/components/FilterableTable/sortResults.ts Outdated
Comment thread superset/dataframe.py Outdated

@bito-code-review bito-code-review Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Agent Run #f49a1c

Actionable Suggestions - 3
  • superset-frontend/src/components/FilterableTable/sortResults.ts - 1
    • CWE-20: Comparator contract violations · Line 59-63
  • tests/unit_tests/dataframe_test.py - 2
Additional Suggestions - 1
  • superset-frontend/src/components/FilterableTable/sortResults.ts - 1
    • Unsafe regex with potential ReDoS · Line 23-23
      The regular expression on line 23 (`DECIMAL`) is flagged as unsafe (CWE-1333) due to nested quantifiers that may cause catastrophic backtracking. A similar issue exists on line 58. Consider simplifying the pattern to avoid nested quantifiers while preserving the same matching behavior.
Review Details
  • Files reviewed - 7 · Commit Range: 0a36b0d..0a36b0d
    • docs/docs/using-superset/number-formatting.mdx
    • superset-frontend/src/components/FilterableTable/exactDecimals.test.tsx
    • superset-frontend/src/components/FilterableTable/index.tsx
    • superset-frontend/src/components/FilterableTable/sortResults.test.ts
    • superset-frontend/src/components/FilterableTable/sortResults.ts
    • superset/dataframe.py
    • tests/unit_tests/dataframe_test.py
  • Files skipped - 1
    • UPDATING.md - Reason: Filter setting
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • Eslint (Linter) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

Comment thread superset-frontend/src/components/FilterableTable/sortResults.ts Outdated
Comment thread tests/unit_tests/dataframe_test.py
Comment thread tests/unit_tests/dataframe_test.py Outdated
@aminghadersohi
aminghadersohi removed the request for review from rusackas September 29, 2026 03:25
Comparing a number against text with < is false in both directions, so
sortResults returned 1 each way and the grid's order depended on the input
order. Numbers compare numerically, everything else (including NaN) as text.
Master routes chart JSON through df_to_records, so decimal quoting is
now opt-out: chart records keep Decimal numbers while SQL Lab callers
quote them. Decimal conversion matches exact types only, like the rest
of df_to_records. Also documents the new decimal tests and renames a
local that read like the stdlib module.
The decimal and numeric-literal patterns nested quantified groups, which
static analysis flags as a backtracking risk. Split the optional sign,
fraction and exponent off by hand so each remaining pattern is one flat
run of digits. A test checks the new parsers against the old patterns on
every string up to five tokens and times adversarial near-miss inputs.
@aminghadersohi

Copy link
Copy Markdown
Contributor Author

Addressed bito's additional suggestion (unsafe regex with nested quantifiers, sortResults.ts line 23 and the similar one on line 58) in 394a03d. Both patterns are replaced with hand-split sign/fraction/exponent parsing, so each remaining regex is a single flat run of digits and matching is linear. A new test checks the parsers against the old patterns on all 111,111 strings of up to five tokens (identical results) and runs 200k-character near-miss inputs under a time bound.

Also merged master in (cd7c69f). Master now sends chart JSON through df_to_records, so decimal quoting is opt-out there: chart records keep Decimal numbers (convert_decimals=False in query_context_processor, with a test), and SQL Lab keeps exact strings.

@bito-code-review

bito-code-review Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #f7252e

Actionable Suggestions - 0
Additional Suggestions - 4
  • superset-frontend/src/components/FilterableTable/sortResults.test.ts - 4
    • Redundant checked counter · Line 88-103
      `checked` is incremented per string (lines 91, 99) and only read by `expect(checked).toBeGreaterThan(100000)` (line 102). The count is fully determined by the alphabet (10 tokens) and `maxLength` 5: 111111 strings — verified by running the same enumeration on Node 20.12.1. The threshold also passes even if `strings` silently returns a truncated enumeration (e.g. after a swallowed spread failure), so it adds a mutable counter without real protection.
    • NaN branch untested · Line 89-92
      The alphabet includes the multi-char tokens `'NaN'` and `'Infinity'` (line 89), but with `maxLength: 5` (line 92) neither can ever appear in an enumerated string (`'NaN'` needs 3 chars only as a whole token — flatMap concatenation can produce it, but `'Infinity'` at 8 chars cannot; and the adversarial test at lines 106-111 never feeds `NaN`-prefixed inputs). The oracle equivalence for the `NaN` branch of `isNumericText` (sortResults.ts line 65) is therefore never actually exercised by either new test — verified by executing the enumeration: 111111 strings, zero containing 'Infinity'.
    • Flaky wall-clock assertion · Line 112-117
      The wall-clock bound `expect(Date.now() - started).toBeLessThan(1000)` (line 117) is a flake risk: measured parse time for the four 200k-char inputs is ~3ms on this machine (Node 20.12.1), but shared CI runners can transiently stall >1s between `Date.now()` samples, failing the test without any parser regression. The repo's jest config sets `testTimeout: 20000`, so a looser bound is consistent with existing practice.
    • Spread RangeError risk · Line 78-86
      `strings()` builds the enumeration with `all.push(...level)`. Spread arguments are subject to the engine's max call-argument limit: on Node 20 a spread of ~1M elements throws `RangeError: Maximum call stack size exceeded`. The limit is 5 today, but raising `maxLength` (e.g. to 7 for the 8-char `Infinity` token) makes the test crash with a RangeError instead of reporting mismatches. Copy per element or use `concat`.
Review Details
  • Files reviewed - 2 · Commit Range: 0a36b0d..394a03d
    • superset-frontend/src/components/FilterableTable/sortResults.test.ts
    • superset-frontend/src/components/FilterableTable/sortResults.ts
  • Files skipped - 0
  • Tools
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • Eslint (Linter) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@EnxDev EnxDev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Went through the backend boundary and the comparator. The chart path staying numeric and the Arrow read path getting the same conversion both check out.

One thing to fix before merge, inline on _convert_decimals: str(Decimal) switches to scientific notation for high-scale values, so zeros in a DECIMAL(38,18) column show up as 0E-18. Plus a small nit on a test comment.

Comment thread superset-frontend/src/components/FilterableTable/sortResults.test.ts Outdated
Comment thread superset/dataframe.py Outdated
str(Decimal) switches to scientific notation for small adjusted
exponents, so DECIMAL(38,18) zeros rendered as 0E-18 and small
negatives such as -0.0000001 were formula-escaped in CSV exports.
Use format(value, "f") to keep every digit and the scale.

Also rename the sort parser test oracles to reference regexes, assert
the exact enumeration size and multi-character tokens, avoid a spread
over the enumeration, and drop the wall-clock bound.
@aminghadersohi

Copy link
Copy Markdown
Contributor Author

Code Review Agent Run #f7252e: redundant checked counter, NaN branch untested, flaky wall-clock assertion, spread RangeError risk

Addressed in 730a8ed: the counter and the Date.now() bound are gone. The test asserts the enumeration has exactly 111,111 entries, and strings() pushes per element rather than spreading. On the NaN point: maxLength counts tokens, not characters, so NaN, Infinity and -Infinity are each one- or two-token strings. The test now asserts they are in the enumeration, so the NaN/Infinity branches of isNumericText are compared against the reference regex. Master merged in 2412b52.

@fitzee fitzee left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: Needs changes (1 only). The backend is correct; items 2–4 are nits.

I verified fe32227 against master locally: SupersetResultSet → _serialize_and_expand_data (JSON and msgpack) → _deserialize_results_payload → CSV export.

  • Output is exact for 38-digit decimal128, 60-digit decimal256, 1E-40, 1E+30/-5E+3, DECIMAL(18,18) 0 and -1E-7, Decimal mixed with int, and NULLs.
  • Chart JSON is still numeric.
  • Payloads written by old and new workers are readable by both sides, so rolling deploys are fine.
  • Targeted and surrounding unit tests pass (6k+).
  1. Sorting numeric columns got ~40x slower (FilterableTable/sortResults.ts:72-86). Every comparison, including number-vs-number, runs String(), regexes, BigInt and padEnd.

    • Node 22, 100k rows: plain numbers 37ms → 1726ms, decimal strings 459 → 1428ms, text 173 → 581ms.
    • At the default DISPLAY_MAX_ROW (10k), numbers go 3 → 125ms.

    Add a fast path at the top, and consider memoizing decimalParts per value:

    if (typeof valueA === 'number' && typeof valueB === 'number' &&
        !Number.isNaN(valueA) && !Number.isNaN(valueB)) {
      return valueA === valueB ? 0 : valueA < valueB ? -1 : 1;
    }
  2. The comparator still isn't transitive (sortResults.ts:101-107). Numeric pairs compare numerically, but number-vs-text pairs compare lexicographically.

    • sortResults('9','10'), ('10','5x') and ('5x','9') all return -1.
    • So [9,'5x',10], [10,9,'5x'] and ['5x',10,9] sort to three different orders.
    • The "sorts a mixed text and number column transitively" test only passes because of the values it uses.

    Order by type first (numeric < text < NaN), then compare within each type. This was already broken on master, but the comment says it's fixed.

  3. Scientific notation is still possible (result_set.py:94). When pyarrow can't infer a decimal type, the column is stringified with str(Decimal). That happens when the column contains Decimal NaN or Infinity (both valid Postgres numeric values), or Decimal mixed with float.

    • [Decimal('Infinity'), Decimal('-0.00000010')] becomes "Infinity", "-1.0E-7", and CSV writes '-1.0E-7 (formula-escaped).
    • Master does the same, but it contradicts "never in scientific notation" in number-formatting.mdx.

    Use format(v, "f") for finite Decimals and None for non-finite ones in stringify_values, or soften the doc line.

  4. Extension API (src/core/sqlLab/index.ts:246): onDidQuerySucceed result.data now carries strings for numeric columns (for example Postgres SUM(bigint)/AVG/ROUND). An extension that adds these values would concatenate them ("12"+"3" = "123"). Please mention extensions in the UPDATING entry.

Every comparison parsed both values, so numeric columns sorted about 30x
slower than before. Compare two JavaScript numbers directly and cache
each value's parsed sort key.

Number-versus-text pairs still compared as text, so [9, '5x', 10] sorted
differently depending on input order. Order by type first (numbers,
including exact decimal strings and infinities, then text, then NaN,
then nulls) and compare within each type. isNumericText only served the
old text fallback and is removed.
When PyArrow cannot type a decimal column (it holds NaN or Infinity, or
Decimals mixed with floats), stringify_values used str(Decimal), which
switches to scientific notation: -0.00000010 became -1.0E-7 and CSV
export formula-escaped it. Use format(value, "f") for finite decimals and
null for NaN and Infinity, which have no exact value.
Listeners of sqlLab.onDidQuerySuccess receive strings for numeric
columns, so arithmetic with + concatenates. Also note fixed-point
notation and null for non-finite decimals.
@aminghadersohi

Copy link
Copy Markdown
Contributor Author

@fitzee thanks for the thorough review. All four points are addressed; master had not moved, so there's no new merge.

  1. Sort performance (8d33239). Your number-vs-number fast path is at the top of sortResults, and each value's parsed sort key is memoized in a bounded cache that clears above 250k entries. Node 22, 100k rows, median of 5:

    Column master fe32227 8d33239
    plain numbers 30 ms 925 ms 32 ms
    decimal strings 500 ms 1294 ms 226 ms
    text 102 ms 467 ms 140 ms

    New tests cover direct number comparisons (-0/0, infinities, 0.1 + 0.2 vs 0.3). They also check that a number and its exact string, such as 1e21 and '1E+21', compare equal, so the fast path agrees with the parsed path.

  2. Transitivity (8d33239). The comparator orders by type first: numbers (exact decimal strings and ±Infinity included), then text, then NaN, then nulls. It then compares within each type. [9,'5x',10], [10,9,'5x'], ['5x',10,9] and their string versions all sort to 9, 10, '5x'. A brute-force test checks reflexivity, antisymmetry and transitivity over every triple of 23 mixed values. The misleading comment is gone, and so is isNumericText, which only served the old text fallback. Six of the new tests fail against the previous comparator. FilterableTable Jest: 67 pass locally.

  3. Scientific notation fallback (0241530). stringify_values uses format(v, "f") for finite Decimals and None for NaN/Infinity. Tests cover [Decimal('Infinity'), Decimal('-0.00000010')] → [None, '-0.00000010'], Decimal NaN/-Infinity/1E+3, and Decimal mixed with float (-0.00000010, 1.5, 0E-18). Each test also asserts the CSV has no apostrophe escape and no E± notation. All three fail before the change. This keeps the "never in scientific notation" line in the docs accurate.

  4. Extension API (1b68a7b). The UPDATING entry says the data rows given to sqlLab.onDidQuerySuccess listeners carry strings for numeric columns, and that + concatenates them. The API is named onDidQuerySuccess in @apache-superset/core. The entry also notes fixed-point notation and null for non-finite decimals.

The PR description is updated with the new behaviour and the benchmark.

@bito-code-review bito-code-review Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Agent Run #eb6d92

Actionable Suggestions - 1
  • superset-frontend/src/components/FilterableTable/sortResults.test.ts - 1
Review Details
  • Files reviewed - 7 · Commit Range: 394a03d..1b68a7b
    • docs/docs/using-superset/number-formatting.mdx
    • superset-frontend/src/components/FilterableTable/sortResults.test.ts
    • superset/dataframe.py
    • tests/unit_tests/dataframe_test.py
    • superset-frontend/src/components/FilterableTable/sortResults.ts
    • superset/result_set.py
    • tests/unit_tests/result_set_test.py
  • Files skipped - 1
    • UPDATING.md - Reason: Filter setting
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • Eslint (Linter) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@EnxDev EnxDev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Second pass. This supersedes my earlier review.

Both earlier points are fixed in 730a8ed. _convert_decimals uses format(value, "f"), the high-scale zero and small negative cases are in the parametrize, and there's a CSV assertion. The reference regex rename landed too. fitzee's four points also check out in the diff: the number fast path, the type-ranked comparator with the total-order test, fixed-point stringify_values, and the extension note. The event name onDidQuerySuccess matches @apache-superset/core.

Two new notes inline. The module-level sort key cache keeps cell values alive after the grid is gone. And the stringify_values change reaches chart queries, which the UPDATING entry says are unchanged. Also, bito's test.each note on sortResults.test.ts:83 is a false positive: each row is [[...]], so column gets the whole array.

Comment thread superset-frontend/src/components/FilterableTable/sortResults.ts Outdated
Comment thread superset/result_set.py
@aminghadersohi
aminghadersohi requested review from EnxDev and removed request for fitzee September 30, 2026 11:03

@EnxDev EnxDev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Third pass, superseding my previous one.

Both notes from last time are fixed at d161f30. The sort key cache is a WeakMap keyed by the rows array, and data is a stable Redux reference in ResultSet, so columns only rebuild on a new result. The UPDATING entry and the guide cover the stringify_values fallback for charts, with tests through Database.load_into_dataframe. I also checked a Postgres-style numeric[] column locally through SupersetResultSet and df_to_records, and the nested decimals come out exact too. CI is green.

Looks good to me. Left two small notes inline, on the convert_decimals default and one gap in the UPDATING entry, plus a test nit you can skip.

Comment thread UPDATING.md
Comment thread superset-frontend/src/components/FilterableTable/sortResults.test.ts Outdated
Comment thread superset/dataframe.py Outdated

@bito-code-review bito-code-review Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Agent Run #ce5235

Actionable Suggestions - 1
  • superset-frontend/src/components/FilterableTable/index.tsx - 1
Additional Suggestions - 3
  • tests/unit_tests/result_set_test.py - 2
    • Duplicate test coverage · Line 691-703
      This parametrize block duplicates `test_stringified_decimals_use_fixed_point` (lines 650-688): the `[Decimal("-0.00000010"), 1.5, Decimal("0E-18")]` case is identical and the non-finite cases overlap. Both exercise the same `SupersetResultSet` stringify path. Consolidate or use distinct cases to avoid divergent maintenance.
    • Test DB side effect · Line 714-714
      `Database.load_into_dataframe` is wrapped by `@event_logger.log_this`, so this test triggers a real `DBEventLogger` DB write (`db.session.commit()`) on every parametrized run. That couples the test to the event-logging stack and pollutes the test DB. Mock `event_logger.log` or call `SupersetResultSet(...).to_pandas_df()` directly.
  • superset-frontend/src/components/FilterableTable/sortResults.test.ts - 1
    • Vacuous cache-pollution guard · Line 237-237
      `sortResults('1.25', '2.50')` without `rows` returns early in `sortKey` (sortResults.ts:129) and never touches `sortKeyCaches`, so `getCachedSortKey('1.25', rows)` here cannot fail — the assertion implies the rows-less path could pollute the cache when it structurally cannot. Drop it; line 236 and the `test.each` at lines 21-50 already cover the rows-less overload.
Review Details
  • Files reviewed - 11 · Commit Range: 1b68a7b..48bf663
    • superset-frontend/src/components/FilterableTable/index.tsx
    • superset-frontend/src/components/FilterableTable/sortResults.test.ts
    • superset-frontend/src/components/FilterableTable/sortResults.ts
    • docs/docs/using-superset/number-formatting.mdx
    • tests/unit_tests/result_set_test.py
    • superset/common/query_context_processor.py
    • superset/dataframe.py
    • superset/sql/execution/celery_task.py
    • superset/sql_lab.py
    • superset/views/utils.py
    • tests/unit_tests/dataframe_test.py
  • Files skipped - 1
    • UPDATING.md - Reason: Filter setting
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful
    • Eslint (Linter) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

Comment thread superset-frontend/src/components/FilterableTable/index.tsx Outdated
@bito-code-review

bito-code-review Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #7124f5

Actionable Suggestions - 0
Review Details
  • Files reviewed - 2 · Commit Range: 48bf663..de3c51c
    • superset-frontend/src/components/FilterableTable/exactDecimals.test.tsx
    • superset-frontend/src/components/FilterableTable/index.tsx
  • Files skipped - 0
  • Tools
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@aminghadersohi

Copy link
Copy Markdown
Contributor Author

Fixed in 8f54a98: the SQL Lab CSV export path without a results backend and the streaming CSV export path now format finite Decimal values as exact fixed-point text, matching the no-scientific-notation promise. Added regression coverage for zero, negative and large exponents, trailing zeros, custom decimal separators, and unchanged non-finite values. Both touched unit-test files pass (35 tests), and pre-commit passes for all five changed files.

@EnxDev EnxDev left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 8f54a98140, including the CSV export follow-up pushed during this pass. No new actionable findings. This supersedes my previous review.

The earlier notes are addressed: convert_decimals defaults to False, all three SQL Lab callers opt in, the result-table extension contract is documented, and the cache test checks key reuse without spying on BigInt. The shared comparator retains the correct rows-array dependency, with rerender coverage. The latest export change also covers re-executed queries and streaming CSV, including custom decimal separators.

@bito-code-review bito-code-review Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Agent Run #1a674f

Actionable Suggestions - 2
  • superset/commands/sql_lab/export.py - 2
Additional Suggestions - 2
  • superset/commands/streaming_export/base.py - 1
    • Decimal handled twice · Line 195-199
      New `Decimal` branch (195-199) overlaps the `(float, Decimal, Real)` tuple at line 203: finite Decimals are caught here, so `Decimal` in that tuple now only reaches non-finite values (NaN/Infinity), which have no `.` to replace. Consider dropping `Decimal` from the tuple to avoid two divergent Decimal paths (fixed vs scientific formatting).
  • tests/unit_tests/commands/sql_lab/streaming_export_command_test.py - 1
    • Missing test local type hints · Line 923-923
      New test locals (`result`, `command`, `buffer`, `writer`, `chunks`, `values`, `formatted`) lack the explicit type annotations BITO.md adaptive rules 12787/13153 mandate for test files, e.g. `result: MagicMock = MagicMock()`. Params and return types are annotated; extend the same coverage to locals so mypy and reviewers see intended types. Applies in both new tests (lines 922-933 and 943-954).
Review Details
  • Files reviewed - 5 · Commit Range: de3c51c..8f54a98
    • docs/docs/using-superset/number-formatting.mdx
    • superset/commands/sql_lab/export.py
    • superset/commands/streaming_export/base.py
    • tests/unit_tests/commands/sql_lab/export_test.py
    • tests/unit_tests/commands/sql_lab/streaming_export_command_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

Comment thread superset/commands/sql_lab/export.py Outdated
@aminghadersohi

Copy link
Copy Markdown
Contributor Author

Fixed both body suggestions in e1fb34c: consolidated Decimal handling and added test-local annotations. NaN/Infinity and custom decimal separators are covered by regression tests. All 55 targeted tests and changed-file pre-commit checks pass.

@rusackas
rusackas merged commit fd524f4 into apache:master Oct 1, 2026
86 checks passed

@rusackas rusackas left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for chasing down fitzee's notes, the number-vs-number fast path and cached sort keys in sortResults.ts take care of the perf regression, and result_set.py's fallback formatting handles the scientific-notation case now too. Also checked commands/sql_lab/export.py's no-cache branch myself since it looked like it could've skipped the same fix, it's routed through _format_decimal_columns now as well. LGTM!

@rusackas rusackas left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for chasing down fitzee's notes, the number-vs-number fast path and cached sort keys in sortResults.ts take care of the perf regression, and result_set.py's fallback formatting handles the scientific-notation case now too. Also checked commands/sql_lab/export.py's no-cache branch myself since it looked like it could've skipped the same fix, it's routed through _format_decimal_columns now as well. LGTM!

@bito-code-review

Copy link
Copy Markdown
Contributor

Bito Automatic Review Skipped – PR Already Merged

Bito scheduled an automatic review for this pull request, but the review was skipped because this PR was merged before the review could be run.
No action is needed if you didn't intend to review it. To get a review, you can type /review in a comment and save it

niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* fix(echarts): fix sparse sub-daily bar sizing and x-axis mislabeling (apache#44628)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mysql): require TLS when SSL is requested (apache#44723)

* fix(dynamodb): render time bounds as ISO 8601 so sub-day ranges match stored timestamps (apache#44702)

* fix(opensearch): page drill-to-detail samples with the OpenSearch SQL response format (apache#44703)

* fix(gsheets): pass the OAuth2 token and delegation subject through connect_args (apache#44709)

* fix(databricks): stop the string-type patch writing SQLAlchemy's shared colspecs (apache#44707)

* fix(oracle): map Oracle NUMBER, BINARY_FLOAT/DOUBLE and CLOB column types (apache#44685)

Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>

* chore(deps): bump undici from 7.29.0 to 7.30.0 in /superset-frontend in the security group across 1 directory (apache#44809)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* chore(deps): bump react-window from 2.3.2 to 2.3.3 in /superset-frontend (apache#44820)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(datafusion): render temporal SQL that DataFusion accepts (apache#44700)

* fix(db2): set current_schema to the catalog name of the selected schema (apache#44706)

* chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /superset-frontend/cypress-base (apache#44813)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* perf(security): memoise the user subject lookup within a request (apache#44017)

Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: shaurya <shauryajaiswal.dev@gmail.com>
Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

* fix(semantic-layer): honor provider preferred time dimension (apache#44997)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* feat(dashboard): add column allowlist to Group By native filter (apache#43736)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(soft-delete): preserve a shared datasource permission on purge (apache#45034)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* perf(versioning): defer capture policy until versioned work (apache#44928)

* fix(date-parser): reject malformed time ranges instead of scanning everything (apache#45098)

* chore(deps-dev): bump wait-on from 9.4.0 to 9.5.1 in /superset-frontend (apache#45048)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps): bump mapbox-gl from 3.31.0 to 3.32.0 in /superset-frontend (apache#45049)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-embedded-sdk (apache#45074)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the swc group across 2 directories with 1 update (apache#45118)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node in /superset-embedded-sdk (apache#45121)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump swagger-ui-react from 5.33.0 to 5.33.1 in /docs (apache#45122)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump yargs from 18.1.0 to 18.2.0 in /superset-frontend (apache#45129)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt in /docs (apache#45119)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
villebro added a commit that referenced this pull request Oct 9, 2026
The duplicate-column-name tests cherry-picked from #44189 use
pytest.mark.parametrize, but on 7.0 result_set_test.py never imported
pytest: on master that import arrived with #44739, which builds on the
excluded #44219 and is not on 7.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

doc Namespace | Anything related to documentation size/XXL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants