Skip to content

fix(semantic-layers): remove child view permissions when a layer is deleted - #44905

Merged
aminghadersohi merged 5 commits into
apache:masterfrom
mikebridge:sc-123444-layer-delete-view-perms
Oct 6, 2026
Merged

aminghadersohi merged 5 commits into
apache:masterfrom
mikebridge:sc-123444-layer-delete-view-perms

Conversation

@mikebridge

@mikebridge mikebridge commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

SUMMARY

Deleting a semantic layer left its views' datasource_access permissions and role grants behind when the views were not loaded in the session, because the cleanup depended on per-view ORM delete events.

Cleanup now runs in a layer before_delete hook on the connection, so it does not depend on whether the views are loaded, and it happens in the same transaction as the delete. A permission that is still in use is kept. That includes a permission a view in another layer uses, and, when a dataset is deleted, a permission a live semantic view still uses.

For the unloaded layer deletion hook used by DeleteSemanticLayerCommand, ownership checks are batched into three fixed-size SELECTs; a 30-child test guards this count. A loaded ORM collection still takes two ownership checks per child.

BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF

N/A (backend cleanup on delete).

TESTING INSTRUCTIONS

  • pytest tests/unit_tests/semantic_layers/models_test.py
  • New tests delete a layer with its views loaded and unloaded and assert the view permissions and role grants are gone; they fail on master in the unloaded case. Further tests assert that a permission still in use survives both a view delete and a layer delete. Regressions cover a key shared with a view in another layer, and a dataset delete whose permission a semantic view still uses.
  • Not covered: large-catalog query plans and concurrent deletes. The permission columns are unindexed; adding indexes to tables.perm and semantic_views.perm is deliberately left to a separate migration change.

ADDITIONAL INFORMATION

  • Has associated issue:
  • Required feature flags:
  • Changes UI
  • Includes DB Migration (follow approval process in SIP-59)
  • Introduces new feature or API
  • Removes existing feature or API

🤖 Generated with Claude Code

Mike Bridge and others added 2 commits October 2, 2026 11:39
…eleted

Deleting a semantic layer whose views were not loaded left each view's
datasource_access PVM and its role grants behind: with passive_deletes
the database ON DELETE CASCADE removes the view rows, so the views' ORM
after_delete hook never runs, and the layer's own hook removed only the
layer's permission. Add a before_delete hook that reads the child view
perms through the connection while the rows still exist and removes their
PVMs and role grants in the same transaction, independent of load state.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
When a semantic view is deleted, directly or with its layer, remove its
datasource_access permission only if no other live resource still owns a
permission with the same name. Otherwise the cleanup would revoke that
resource's grants along with the deleted view's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 94.28571% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.26%. Comparing base (e606cad) to head (837a741).
⚠️ Report is 95 commits behind head on master.

Files with missing lines Patch % Lines
superset/security/manager.py 93.54% 0 Missing and 2 partials ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master   #44905      +/-   ##
==========================================
+ Coverage   82.14%   82.26%   +0.11%     
==========================================
  Files        2995     2996       +1     
  Lines      184988   185580     +592     
  Branches    42814    42928     +114     
==========================================
+ Hits       151960   152663     +703     
+ Misses      30269    30162     -107     
+ Partials     2759     2755       -4     
Flag Coverage Δ
hive 36.26% <17.14%> (-0.05%) ⬇️
mysql 55.22% <48.57%> (-0.12%) ⬇️
postgres 55.23% <48.57%> (-0.13%) ⬇️
presto 38.13% <17.14%> (-0.05%) ⬇️
python 86.32% <91.42%> (+0.19%) ⬆️
sqlite 54.96% <48.57%> (-0.12%) ⬇️
unit 79.38% <88.57%> (+0.28%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mikebridge
mikebridge marked this pull request as ready for review October 2, 2026 22:11

sa.event.listen(SemanticLayer, "after_insert", SemanticLayer.after_insert)
sa.event.listen(SemanticLayer, "before_update", SemanticLayer.before_update)
sa.event.listen(SemanticLayer, "before_delete", SemanticLayer.before_delete)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: Deleting a layer now performs multiple permission queries per child view, causing a large layer deletion to issue O(n) database round trips and become unnecessarily slow.

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes · 🏷️ Performance

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** superset/semantic_layers/models.py
**Line:** 842:842
**Comment:**
	*Performance: Deleting a layer now performs multiple permission queries per child view, causing a large layer deletion to issue O(n) database round trips and become unnecessarily slow.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

@bito-code-review

Copy link
Copy Markdown
Contributor

The flagged performance issue is correct. The current implementation of semantic_layer_before_delete performs a database query for every child view to check if its permission is owned elsewhere, leading to O(n) round trips.

To resolve this, you can optimize the permission ownership check by batching the queries. Instead of querying for each view individually, you can fetch all relevant permissions in a single query or use a more efficient set-based approach to identify which permissions are still in use by other resources.

superset/security/manager.py

def _semantic_view_perm_owned_elsewhere(
        self,
        connection: Connection,
        perm: str,
        deleted_view_ids: set[int],
    ) -> bool:
        # ... (existing logic)
        # Optimization: Consider fetching all used permissions in one query
        # and checking against that set instead of querying per-permission.
        return (
            connection.execute(
                sv_table.select()
                .where(sv_table.c.perm == perm, sv_table.c.id.not_in(deleted_view_ids))
                .limit(1)
            ).first()
            is not None
        )

@bito-code-review bito-code-review Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Agent Run #089298

Actionable Suggestions - 2
Review Details
  • Files reviewed - 3 · Commit Range: d010870..bbb22ad
    • superset/security/manager.py
    • superset/semantic_layers/models.py
    • tests/unit_tests/semantic_layers/models_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

Comment thread superset/security/manager.py Outdated
Comment on lines +4363 to +4366
for view_row in views:
if view_row.perm and not self._semantic_view_perm_owned_elsewhere(
connection, view_row.perm, deleted_view_ids
):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

N+1 queries in delete hook

Each iteration of the views loop calls _semantic_view_perm_owned_elsewhere, which issues two queries (datasets.perm and semantic_views.perm lookups). Deleting a layer with N child views runs 2N+1 queries inside the flush. Consider batching: collect distinct perms, resolve ownership with one query per table, then delete the PVMs.

Code Review Run #089298


Should Bito avoid suggestions like this for future reviews? (Manage Rules)

  • Yes, avoid them

Comment on lines +4392 to +4402
if connection.execute(
table.select().where(table.c.perm == perm).limit(1)
).first():
return True
sv_table = SemanticView.__table__ # pylint: disable=no-member
return (
connection.execute(
sv_table.select()
.where(sv_table.c.perm == perm, sv_table.c.id.not_in(deleted_view_ids))
.limit(1)
).first()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unindexed perm equality scans

SqlaTable.perm and SemanticView.perm are unindexed String(1000) columns; the equality lookups here full-scan datasets and semantic_views, once per deleted view (see the loop in semantic_layer_before_delete). An index on perm would bound this cleanup cost on large deployments.

Code Review Run #089298


Should Bito avoid suggestions like this for future reviews? (Manage Rules)

  • Yes, avoid them

@aminghadersohi aminghadersohi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blockers: the cascade premise holds (migration declares ON DELETE CASCADE, SQLite FK pragma is on) and perms are unique per view via the (id:N) suffix. Mutants forcing the ownership check True/False, or dropping the SqlaTable lookup, the not_in clause or the listener, all fail the new tests.


A deleted view's permission is removed only when no dataset and no
other semantic view still uses the same permission name; removing it
would otherwise revoke that resource's grants.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking: the guard is one-way. dataset_after_delete (superset/security/manager.py L3958, outside this diff) still drops the PVM unconditionally, so deleting the colliding dataset revokes grants on the semantic view this PR now protects. Same check there would close it; fine as a follow-up.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for pointing out the reverse deletion path. Fixed in 89dec7f: dataset deletion now checks whether a live semantic view still owns the permission before removing its grants. A red-first test reproduces the previous revocation and verifies the grant survives.

def test_layer_delete_removes_child_view_permissions(
session: Any, children_loaded: bool
) -> None:
"""sc-123444: deleting a layer removes each child view's datasource_access

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: internal tracker IDs carry no meaning in apache/superset; suggest dropping it here and on L2447.

Suggested change
"""sc-123444: deleting a layer removes each child view's datasource_access
"""Deleting a layer removes each child view's datasource_access

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed. 89dec7f removes the internal tracker reference from the test docstring and gives it a complete first-line summary.

)
session.add(layer)
session.flush()
# Two children: while ``semantic_views`` is mapped as a scalar (SC-123445),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here.

Suggested change
# Two children: while ``semantic_views`` is mapped as a scalar (SC-123445),
# Two children: while ``semantic_views`` is mapped as a scalar,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed. 89dec7f removes the internal tracker reference and describes the loaded ORM and unloaded database-cascade cases directly.

@gabotorresruiz gabotorresruiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @mikebridge, LGTM. The shape is right: the hook runs on the connection inside the same flush as the layer DELETE, the loaded children are deleted by the ORM first and clean up in semantic_view_after_delete, and the ones left to ON DELETE CASCADE are read while their rows still exist, so no path leaves ab_permission_view_role or ab_permission_view rows behind. I also confirmed the scalar mapping the test comment mentions (semantic_views reports uselist=False at runtime), so until that is fixed the new hook is what carries every child past the first; good that the fix does not depend on it. Ran tests/unit_tests/semantic_layers/models_test.py here (115 passing) and the five new cases on the merge base, where four fail (the loaded-children case too, for the same scalar-mapping reason). Agree with Amin on dropping the tracker ids from the test and on the dataset_after_delete follow-up. CI is green. One small nit inline.

Comment thread superset/security/manager.py Outdated

sv_table = SemanticView.__table__ # pylint: disable=no-member
views: Sequence[Row[Any]] = connection.execute(
sv_table.select().where(sv_table.c.semantic_layer_uuid == target.uuid)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a small NIT: this pulls every column of every child view, including configuration, when the loop only reads id and perm. select(sv_table.c.id, sv_table.c.perm) keeps the hook cheap on a layer with many or large views. semantic_layer_before_update does the same today, so feel free to leave it for consistency. Not a blocker.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, good catch. The later batch-cleanup commit already changed the layer-deletion hook to select only perm, so it no longer loads each view's configuration.

I added a regression assertion in 837a741 that keeps all of the ownership SELECTs narrow; the focused models and security tests pass. The separate update hook is unchanged, since it is outside this deletion-path change.

@codeant-ai-for-open-source

codeant-ai-for-open-source Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

CodeAnt PR Risk: Low Risk

  • The PR appears safe to merge; permission cleanup preserves grants shared with datasets or other semantic views.
  • Layer deletion uses a bounded set of ownership queries, and tests cover loaded and database-cascaded child views.

Assessed commit: 837a7410437e

@netlify

netlify Bot commented Oct 6, 2026

Copy link
Copy Markdown

✅ Deploy Preview for superset-docs-preview ready!

Name Link
🔨 Latest commit 80a405d
🔍 Latest deploy log https://app.netlify.com/projects/superset-docs-preview/deploys/6ac45060c6dc0d000895078e
😎 Deploy Preview https://deploy-preview-44905--superset-docs-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@bito-code-review

bito-code-review Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #0eea76

Actionable Suggestions - 0
Additional Suggestions - 3
  • tests/unit_tests/semantic_layers/models_test.py - 2
    • Inconsistent fixture type annotation · Line 2591-2591
      The new test annotates the fixture as `session: Session` while every sibling test in this file (`test_layer_delete_batches_permission_ownership_queries` line 2486, `test_view_delete_keeps_permission_another_resource_owns` line 2540, `test_dataset_delete_keeps_permission_a_semantic_view_owns` line 2649) uses `session: Any`. The mixed annotations in one file are inconsistent; align them in one direction.
    • CWE-476: Unguarded Lookup Dereference · Line 2644-2644
      `session.get(SemanticView, retained_view_id)` can return `None`, so `.perm` on line 2644 would raise `AttributeError` instead of a clean assertion failure if the layer delete cascaded the retained view. The test already guards the equivalent lookup with `assert pvm is not None` (line 2625); add the same guard here. ([CWE-476](https://cwe.mitre.org/data/definitions/476.html))
  • superset/security/manager.py - 1
    • Duplicated perm-ownership rule · Line 4385-4406
      The rule 'a datasource_access PVM survives while a dataset or another semantic view owns the perm' is now encoded in three places: the guard in `dataset_after_delete`, the batch queries here, and `_semantic_view_perm_owned_elsewhere`. The batch form rightly avoids the old N+1 loop, but parallel encodings can diverge silently (e.g. when a third owner type is added). Consider extracting one set-based helper shared by both paths.
Review Details
  • Files reviewed - 2 · Commit Range: bbb22ad..80a405d
    • superset/security/manager.py
    • tests/unit_tests/semantic_layers/models_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@aminghadersohi
aminghadersohi merged commit d6c871a into apache:master Oct 6, 2026
69 checks passed
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* fix(echarts): fix sparse sub-daily bar sizing and x-axis mislabeling (apache#44628)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mysql): require TLS when SSL is requested (apache#44723)

* fix(dynamodb): render time bounds as ISO 8601 so sub-day ranges match stored timestamps (apache#44702)

* fix(opensearch): page drill-to-detail samples with the OpenSearch SQL response format (apache#44703)

* fix(gsheets): pass the OAuth2 token and delegation subject through connect_args (apache#44709)

* fix(databricks): stop the string-type patch writing SQLAlchemy's shared colspecs (apache#44707)

* fix(oracle): map Oracle NUMBER, BINARY_FLOAT/DOUBLE and CLOB column types (apache#44685)

Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>

* chore(deps): bump undici from 7.29.0 to 7.30.0 in /superset-frontend in the security group across 1 directory (apache#44809)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* chore(deps): bump react-window from 2.3.2 to 2.3.3 in /superset-frontend (apache#44820)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(datafusion): render temporal SQL that DataFusion accepts (apache#44700)

* fix(db2): set current_schema to the catalog name of the selected schema (apache#44706)

* chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /superset-frontend/cypress-base (apache#44813)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* perf(security): memoise the user subject lookup within a request (apache#44017)

Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: shaurya <shauryajaiswal.dev@gmail.com>
Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

* fix(semantic-layer): honor provider preferred time dimension (apache#44997)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* feat(dashboard): add column allowlist to Group By native filter (apache#43736)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(soft-delete): preserve a shared datasource permission on purge (apache#45034)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* perf(versioning): defer capture policy until versioned work (apache#44928)

* fix(date-parser): reject malformed time ranges instead of scanning everything (apache#45098)

* chore(deps-dev): bump wait-on from 9.4.0 to 9.5.1 in /superset-frontend (apache#45048)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps): bump mapbox-gl from 3.31.0 to 3.32.0 in /superset-frontend (apache#45049)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-embedded-sdk (apache#45074)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the swc group across 2 directories with 1 update (apache#45118)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node in /superset-embedded-sdk (apache#45121)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump swagger-ui-react from 5.33.0 to 5.33.1 in /docs (apache#45122)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump yargs from 18.1.0 to 18.2.0 in /superset-frontend (apache#45129)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt in /docs (apache#45119)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
villebro pushed a commit that referenced this pull request Oct 9, 2026
…eleted (#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
(cherry picked from commit d6c871a)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants