Skip to content

fix(embedded): refuse guest row-level security on semantic views - #44987

Merged
sadpandajoe merged 5 commits into
apache:masterfrom
mikebridge:sc-123439-semantic-guest-rls-block
Oct 6, 2026
Merged

sadpandajoe merged 5 commits into
apache:masterfrom
mikebridge:sc-123439-semantic-guest-rls-block

Conversation

@mikebridge

Copy link
Copy Markdown
Contributor

SUMMARY

Row-level security is not supported for semantic views in the MVP. Embedded requests whose guest token carries an applicable RLS rule (a global rule, or one scoped to the semantic view) are now refused with a clear error ("Semantic views cannot enforce guest row-level security rules.") instead of being served. This applies to semantic chart queries and their cached results, column-value suggestions, and the MCP get_table tool.

Semantic views with no applicable guest rule are unaffected. SQL dataset queries continue to enforce their applicable guest rules as before; a chart that also requests semantic content (for example a semantic-backed annotation layer) is subject to the semantic-view restriction for that content. The embedding docs describe the restriction.

BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF

N/A (backend).

TESTING INSTRUCTIONS

  • pytest tests/unit_tests/security/semantic_guest_rls_test.py tests/unit_tests/mcp_service/semantic_layer/tool/test_get_table.py
  • Covers: global guest rules and rules scoped to the semantic view are refused for execution, cached reads, the values endpoint and MCP get_table; guests without an applicable rule and non-guest users are unaffected; SQL datasets still apply guest RLS.

ADDITIONAL INFORMATION

  • Has associated issue:
  • Required feature flags: SEMANTIC_LAYERS, and EMBEDDED_SUPERSET for the embedded path
  • Changes UI
  • Includes DB Migration (follow approval process in SIP-59)
  • Introduces new feature or API
  • Removes existing feature or API

🤖 Generated with Claude Code

mikebridge and others added 4 commits October 5, 2026 09:46
Row-level security is not supported for semantic views in the MVP, so an
embedded request whose guest token carries an applicable RLS rule (a global
rule, or one scoped to the semantic view) is refused with a clear error.
This covers semantic queries, cached results, column values and the MCP
get_table tool. Semantic views without an applicable guest rule, and SQL
datasets, behave as before.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…guest-rls-block

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Register the new error message in the translation template, and make the
guest RLS test provider an unversioned semantic view so the value
suggestions control matches the current values endpoint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Word the embedding note as a rule scoped to the semantic view, and align
the guest RLS test docstrings and one test name with the MVP restriction.
Wording only; no behaviour, assertion or fixture changes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@bito-code-review

bito-code-review Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #e76a83

Actionable Suggestions - 0
Review Details
  • Files reviewed - 7 · Commit Range: e8647a9..80d88bd
    • docs/docs/using-superset/embedding.mdx
    • superset/common/query_context_processor.py
    • superset/security/manager.py
    • superset/semantic_layers/models.py
    • superset/translations/messages.pot
    • tests/unit_tests/mcp_service/semantic_layer/tool/test_get_table.py
    • tests/unit_tests/security/semantic_guest_rls_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@netlify

netlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for superset-docs-preview ready!

Name Link
🔨 Latest commit 7f61aa4
🔍 Latest deploy log https://app.netlify.com/projects/superset-docs-preview/deploys/6ac4799c3e836700080032ba
😎 Deploy Preview https://deploy-preview-44987--superset-docs-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions github-actions Bot added i18n Namespace | Anything related to localization doc Namespace | Anything related to documentation labels Oct 5, 2026
@codecov

codecov Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.36%. Comparing base (7a2913e) to head (7f61aa4).
⚠️ Report is 21 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff             @@
##           master   #44987       +/-   ##
===========================================
+ Coverage   57.31%   82.36%   +25.04%     
===========================================
  Files        2997     2997               
  Lines      185294   185535      +241     
  Branches    42888    42939       +51     
===========================================
+ Hits       106198   152809    +46611     
+ Misses      78056    29972    -48084     
- Partials     1040     2754     +1714     
Flag Coverage Δ
hive 36.30% <9.09%> (+<0.01%) ⬆️
mysql 55.28% <45.45%> (?)
postgres 55.29% <45.45%> (?)
presto 38.17% <45.45%> (-0.01%) ⬇️
python 86.30% <100.00%> (+48.08%) ⬆️
sqlite 55.01% <45.45%> (?)
unit 79.33% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sadpandajoe sadpandajoe added the review:checkpoint Last PR reviewed during the daily review standup label Oct 5, 2026

@aminghadersohi aminghadersohi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The dataset.id change is safe: every .data builder sets "id": self.id, and it also stops rule matching from loading provider metadata. One-clause mutants at all four refusal sites each fail tests, and MCP get_table enforces through view.raise_for_access; two non-blocking notes inline.

Comment thread docs/docs/using-superset/embedding.mdx Outdated

- **Guest tokens expire** — their lifetime is controlled by the `GUEST_TOKEN_JWT_EXP_SECONDS` config (default: 5 minutes). Refresh tokens before they expire using a token refresh mechanism in your host app.
- **Row-level security** — pass `rls` rules in the guest token request to restrict which rows are visible to the embedded user.
- **Row-level security** — pass `rls` rules in the guest token request to restrict which rows are visible to the embedded user. Semantic views cannot enforce guest-token SQL clauses, so queries and cached-result reads are rejected when a global rule or a rule scoped to the semantic view applies. Read permissions do not override these restrictions. Semantic views remain accessible when no guest rule applies; SQL datasets continue to enforce their applicable rules.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Guest rls rules carry only a bare dataset integer, and SQL datasets and semantic views have separate ID spaces, so a rule meant for SQL dataset 7 also refuses semantic view 7. A single global rule also refuses every semantic view. Both fail closed, but worth stating here for hosts.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for calling this out. Both cases deliberately fail closed; I've added a short host-facing note in 7f61aa4, and typed datasource matching is handled in #45002.

datasource = self._qc_datasource
datasource: Explorable = self._qc_datasource
# Reject unenforceable restrictions before provider identity or cache reads.
rls: list[str] = security_manager.get_rls_cache_key(datasource)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SemanticView.get_extra_cache_keys returns [], so this hoist has no observable effect at this head; moving the call back below it passes all 1682 tests in the touched suites. To lock the ordering, give get_extra_cache_keys an AssertionError side_effect in the cached-read test.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. In 7f61aa4 the cached-read test makes extra-cache-key collection raise if it is reached before the guest-RLS refusal. Moving the RLS check below it fails all four restricted cases; with the current ordering all 25 tests in the file pass.

@gabotorresruiz gabotorresruiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @mikebridge, thanks for this one. Embedded plus row level security is exactly the surface where I would rather see a refusal than a best effort enforcement, so the direction here reads right to me.

I checked out the head and walked every way a guest can reach semantic rows: chart data (POST /api/v1/chart/data and GET /api/v1/chart/<pk>/data/) across every result_type and result_format, CSV and XLSX export, StreamingCSVExportCommand, samples, drill to detail, post processing, the cache only read with force_cached, async submit and worker keying in superset/tasks/async_queries.py, the /column/<col>/values/ suggestions route, chart backed annotation layers, execute_tabular_query, and the MCP tools. Each one refuses through either ChartDataCommand.validate or query_cache_key, and in both cases the refusal lands before the provider is touched, while a guest carrying no applicable rule is unaffected on all of them. The cache question comes out clean too: a restricted guest never gets a cache key at all, so there is no entry for it to read, and since RowLevelSecurityFilter.tables only references SqlaTable, a guest token rule is the only kind of RLS that can apply to a semantic view in the first place.

Locally I ran tests/unit_tests/security plus tests/unit_tests/datasource (495 passed), tests/unit_tests/common plus tests/unit_tests/semantic_layers plus tests/unit_tests/charts (1383 passed, 1 failure in test_get_data_json_preserves_browser_numeric_contract that is a numpy longdouble platform artefact and reproduces identically on the merge base), and tests/unit_tests/mcp_service/semantic_layer (145 passed). I also replayed the new tests against the merge base: 15 of the 27 cases fail there and the 12 that pass are the controls, which is the shape I want on a security fix.

CI is green on every required check at 80d88bd. Two non-blocking notes inline, both about wording rather than behaviour.

SupersetError(
error_type=SupersetErrorType.DATASOURCE_SECURITY_ACCESS_ERROR,
message=_(
"Semantic views cannot enforce guest row-level security rules."

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker. The summary says the refusal comes back with a clear error, and that holds for the /column/<col>/values/ route, but not for the chart data routes: both handlers in superset/charts/data/api.py map SupersetSecurityException to a bare response_403(), so a restricted guest gets 403 {"message":"Forbidden"} and this message only reaches the server log. I drove that on this branch across every result_type and result_format on POST /api/v1/chart/data, and all of them refuse before the provider is called (which is the part that matters) but none of them carry the reason.

That is the endpoint's pre-existing shape rather than anything you changed here, so the cheapest fix is probably to reword the docs line to say the reason is in the server log. Or is there a guest redaction rule that intends it this way and I am reading it backwards?

"""
datasource = self._qc_datasource
datasource: Explorable = self._qc_datasource
# Reject unenforceable restrictions before provider identity or cache reads.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not a blocker, more a note on the wording. Because _annotation_cache_context runs inside query_cache_key, this is not the only get_rls_cache_key call that can refuse here: the annotation branch below it calls the same helper on the source chart's datasource, so a plain SQL dataset chart that merely carries a semantic-backed annotation layer is refused in full for a guest with an applicable rule, and its own SQL rows never render either.

I confirmed it on this branch: a SqlaTable host chart with one sourceType: "line" layer resolving to a semantic view refuses, while the same chart with an ordinary SQL annotation source keys normally and still applies the guest rule. Failing closed is the right call, but the summary reads as though only the semantic content is affected, so one clause in embedding.mdx noting that a semantic-backed annotation layer takes the whole chart down for a restricted guest would save a host some debugging.

Address Amin review threads r4187265587 and r4187265602: clarify deliberate semantic refusal for hosts, and make premature extra-cache-key collection fail the cached-read test. The mutation control proves the assertion detects reordered RLS validation without changing production behavior.
@codeant-ai-for-open-source

Copy link
Copy Markdown
Contributor

CodeAnt PR Risk: Low Risk

  • The PR appears safe to merge; semantic-view requests are denied when an applicable guest RLS rule cannot be enforced.
  • Added tests cover query execution, cached reads, values endpoints, MCP access, and continued SQL-dataset RLS enforcement.

Assessed commit: 7f61aa457650

@bito-code-review

bito-code-review Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Agent Run #5db5ca

Actionable Suggestions - 0
Review Details
  • Files reviewed - 2 · Commit Range: 80d88bd..7f61aa4
    • docs/docs/using-superset/embedding.mdx
    • tests/unit_tests/security/semantic_guest_rls_test.py
  • Files skipped - 0
  • Tools
    • MyPy (Static Code Analysis) - ✔︎ Successful
    • Astral Ruff (Static Code Analysis) - ✔︎ Successful
    • Whispers (Secret Scanner) - ✔︎ Successful
    • Detect-secrets (Secret Scanner) - ✔︎ Successful

Bito Usage Guide

Commands

Type the following command in the pull request comment and save the comment.

  • /review - Manually triggers an incremental AI Review.

  • /review full - Manually triggers a full AI Review.

  • /pause - Pauses automatic reviews on this pull request.

  • /resume - Resumes automatic reviews.

  • /resolve - Marks all Bito-posted review comments as resolved.

  • /abort - Cancels all in-progress reviews.

Refer to the documentation for additional commands.

Configuration

This repository uses Superset You can customize the agent settings here or contact your Bito workspace admin at evan@preset.io.

Documentation & Help

AI Code Review powered by Bito Logo

@sadpandajoe sadpandajoe removed the review:checkpoint Last PR reviewed during the daily review standup label Oct 6, 2026
@sadpandajoe
sadpandajoe merged commit c30ae9f into apache:master Oct 6, 2026
74 checks passed
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* fix(echarts): fix sparse sub-daily bar sizing and x-axis mislabeling (apache#44628)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mysql): require TLS when SSL is requested (apache#44723)

* fix(dynamodb): render time bounds as ISO 8601 so sub-day ranges match stored timestamps (apache#44702)

* fix(opensearch): page drill-to-detail samples with the OpenSearch SQL response format (apache#44703)

* fix(gsheets): pass the OAuth2 token and delegation subject through connect_args (apache#44709)

* fix(databricks): stop the string-type patch writing SQLAlchemy's shared colspecs (apache#44707)

* fix(oracle): map Oracle NUMBER, BINARY_FLOAT/DOUBLE and CLOB column types (apache#44685)

Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>

* chore(deps): bump undici from 7.29.0 to 7.30.0 in /superset-frontend in the security group across 1 directory (apache#44809)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* chore(deps): bump react-window from 2.3.2 to 2.3.3 in /superset-frontend (apache#44820)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(datafusion): render temporal SQL that DataFusion accepts (apache#44700)

* fix(db2): set current_schema to the catalog name of the selected schema (apache#44706)

* chore(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /superset-frontend/cypress-base (apache#44813)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* perf(security): memoise the user subject lookup within a request (apache#44017)

Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Daniel Vaz Gaspar <danielvazgaspar@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: shaurya <shauryajaiswal.dev@gmail.com>
Co-authored-by: Shaurya <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
niteshpurohit added a commit to HiMamaInc/superset that referenced this pull request Oct 9, 2026
* refactor(mcp): one plugin lifecycle contract and compact chart config schemas (apache#44746)

* fix(doris): quarter grain, SSL toggle, parameters URI, error mapping and column types (apache#44718)

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44824)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* test(semantic-views): wait for views refetches to settle before selecting a view (apache#44792)

* chore(build): remove unused dependencies in `docs` and `superset-frontend` (apache#44697)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* chore(deps): bump the security group across 1 directory with 2 updates (apache#44831)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: avoid provider calls when rendering datasource access denials (apache#44432)

* fix(csv-import): add primary key when MySQL requires one (apache#44411)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(mcp): align histogram and waterfall query contracts (apache#44744)

* ci(python): run the Python-next canary nightly, bump to 3.13 (apache#44767)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend in the security group across 1 directory (apache#44830)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(matrixify): fan metrics-axis selection into multi-query fields (apache#44629)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqllab): ignore non-object template_params in format_sql instead of 500 (apache#44826)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(core): stop discarding API errors that quote an HTML tag (apache#42489)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(i18n): make babel_update.sh .pot normalization actually run (apache#44395)

* fix(sql): reject client-side file-transfer statements in query execution (apache#44496)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(sqllab): preserve exact decimals in results and exports (apache#44739)

* fix(exasol): classify common server errors (apache#44721)

* fix(elasticsearch): classify byte, short, half_float, scaled_float and unsigned_long columns (apache#44713)

* fix(db2): accept sqlglot's parse_mod in the DB2 term parser (apache#44708)

* fix(databricks): keep the user's OAuth2 token and extra connect_args; re-auth on HTTP 401 (apache#44705)

* fix(gsheets): align service-account validation and serialize upload dates (apache#44695)

* fix(mcp): prioritize exact tool names in BM25 search (apache#44682)

* test(embedded-sdk): cross-document test rig for the navigation fix (apache#44608)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(auth): drain flash messages on the login page (apache#44605)

* fix(gantt): prevent y-axis category labels from being clipped (apache#44321)

* fix(auth): remove the legacy FAB password reset views and move password resets into the SPA (apache#44626)

Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix: increase dataset edit modal size (apache#38215) (apache#39257)

Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(doris): offer the connection form by matching the installed driver (apache#44736)

* chore(deps): bump @googleapis/sheets from 18.0.0 to 18.0.1 in /superset-frontend (apache#44862)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 (apache#44861)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump github/codeql-action/upload-sarif from 4.38.1 to 4.38.2 (apache#44859)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: add sadpandajoe as a codeowner for .asf.yaml (apache#44855)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: drop cypress-matrix-required from required status checks (apache#44854)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (apache#44860)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(e2e): remove Cypress infrastructure (apache#44829)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(oauth2): refresh a token rejected when a connection opens (apache#44765)

* feat(table): add multi-level column header groups (apache#43938)

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): enforce tool deadlines without blocking the server (apache#44581)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(playwright): select existing dashboards without creating duplicates (apache#44856)

* feat(mcp): support tab-scoped dashboard layouts (apache#44797)

* fix: size 'Drill to detail' table header correctly (apache#44807)

* fix(mcp): use DEFAULT_PAGE_SIZE constant in list_charts test (apache#44786)

* fix(mcp): keep a bubble chart's colors and row limit across updates (apache#44618)

Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(frontend): use html2canvas for chart image export on Safari (apache#44529)

* chore(deps): bump deck.gl and luma.gl from 9.2.5 to 9.4.0 in /superset-frontend (apache#42608)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(home): redirect users without an ID before rendering (apache#44456)

* chore(deps-dev): update google-cloud-storage requirement from >=1.37 to >=3.14.1 (apache#44693)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(mcp): enforce dashboard filter scope on dataset, SQL and chart tool calls (apache#44800)

* fix(postprocessing): preserve NULL index values through pivot() (apache#43547) (apache#43693)

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): execute_sql request limit caps, never raises, an explicit SQL LIMIT (apache#44604)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* ci: require babel-extract to pass before merging master (apache#44543)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(mcp): report a chart's live dataset id and name (apache#44681)

* fix(retention): skip models without purge policies before scanning (apache#44874)

* fix(semantic-layers): export/import semantic-view charts by typed reference (apache#44396)

* fix(semantic-layer): require explicit member identity reselection (apache#44370)

* fix(logging): register LogRestApi only once (apache#44732)

* chore(deps-dev): bump baseline-browser-mapping from 2.11.25 to 2.11.26 in /superset-frontend (apache#44890)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dompurify from 3.4.15 to 3.4.16 in /superset-frontend (apache#44889)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dom-to-image-more from 3.10.2 to 3.11.0 in /superset-frontend (apache#44888)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump maplibre-gl from 6.8.0 to 6.11.2 in /superset-frontend (apache#44887)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump minimizer-webpack-plugin from 5.11.0 to 5.12.0 in /superset-frontend (apache#44886)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.1 to 3.5.3 in /superset-frontend (apache#44885)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /docs (apache#44883)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint-tsgolint from 7.0.2002 to 7.0.2003 in /superset-websocket (apache#44882)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(superset-ui-chart-controls): forward-compat fixes for TypeScript 6.0 (apache#44877)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(export/import): add annotation layer export/import support for charts and dashboards (apache#43232)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* fix(users): stop update_me setting self-referential changed_by_fk (apache#44866)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps): bump dawidd6/action-download-artifact from 24 to 25 (apache#44884)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): de-vendor `helm/chart-testing-action` GHA (apache#44722)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(ci): floor pyfakefs at 5.7.4 to fix Python 3.13 pytest-cov crash (apache#44853)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* docs(databases): add ClickHouse Managed Postgres (apache#44870)

Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>

* test(explore): cover time range frames, comparison labels, and metric popover state (apache#44847)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(change-detector): classify changed files by language, not directory (apache#44895)

* chore(mcp): fix malformed tool and prompt docstrings (apache#44572)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* feat(chart): cross-filter by x-axis label on charts with dimensions (apache#44869)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover color scheme selection, BigNumber subheader/trendline, and WorldMap bubbles (apache#44846)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(plugin-chart-table): cover server-side sort, query mode controls, and sort ordering (apache#44845)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): cover viz switch and control dependency logic (apache#44842)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(explore): add fetchTopNValues unit tests (apache#44841)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add saveModalReducer unit tests (apache#44839)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(dashboard): show the configured refresh warning alongside the limit error (apache#44836)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): add datasourcesReducer unit tests (apache#44840)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* test(explore): port remaining deleted Cypress explore specs to RTL (apache#44838)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(frontend): await the userEvent calls that needed restructuring (apache#44799)

* fix(chart): wrap raw pandas TypeError/DataError from post-processing as QueryObjectValidationError (apache#44463)

* fix(reports): catch TypeError when validating non-string extra.dashboard.anchor (apache#44404)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(import): avoid UnboundLocalError when load_yaml fails during load_configs (SC-121288) (apache#44390)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): return 401 not 500 for auth errors in CurrentUserRestApi (SC-120417) (apache#44213)

* fix(security): guard is_guest_user against NoAuthorizationError on unauthenticated error paths (apache#43826)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix: downgrade deprecated query_object field warnings to info (apache#43520)

* docs: remove stale Selenium references after Playwright-only switch (apache#44243)

* fix(mcp): include feature_availability in instance://metadata resource (apache#44891)

* fix(echarts): recognize Date and ISO-string temporal x-axis values in getXAxisDomain (apache#44818)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(native-filters): keep cascade dependency gate in sync with live filter type (apache#44366)

Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(ci): add Chromatic visual regression testing for Storybook (apache#44103)

Co-authored-by: Claude Code <noreply@anthropic.com>

* fix(mcp): skip dashboard live updates when websockets are disabled or realtime access is missing (apache#44796)

* test(dashboard): cover "View as table" end-to-end for a view-as-table-only role (apache#44881)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(clickhouse): cover GROUP BY ALL against a real instance (apache#40482) (apache#44879)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sec): sanitize HTML text before shown as impact item's label (apache#43825)

* fix(chart): accept quarter and day in end-of time ranges (apache#43204)

* fix(sql-lab): avoid duplicate generated result column names (apache#44189)

* fix(chart): sort Heatmap Y-axis by default when unset (apache#44588)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(select): remove Space wrapper from optionRender to fix option label truncation (apache#44357)

* fix(sql-lab): use function valueGetter for GridTable row numbers (apache#41574)

Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>

* fix(mcp): stop partial-update tools from advertising null defaults (apache#44573)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* fix(cartodiagram): share Pie colors across locations in Explore (apache#44794)

* fix(mcp): use create_proxy in simple_proxy for fastmcp 4 compatibility (apache#44787)

* fix(post-processing): stop treating gaps as zero for cumprod, cummin and cummax (apache#44828)

* fix(import): remove duplicate config redefinition in load_configs (apache#44932)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* perf(deletion-retention): one window pass for repeat predicate (apache#44349)

* chore(deps): bump markdown from 3.10.3 to 3.11 (apache#44941)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update google-cloud-storage requirement from >=3.14.1 to >=3.15.0 (apache#44940)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump cachetools from 7.1.8 to 7.2.0 (apache#44939)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): update databricks-sql-connector requirement from <4.6.0,>=4.5.0 to >=4.6.0,<4.7.0 (apache#44937)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump holidays from 0.104 to 0.105 (apache#44936)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps): bump sqlglot from 30.18.0 to 30.19.0 (apache#44935)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(deps-dev): bump clickhouse-connect from 1.8.0 to 1.9.0 (apache#44934)

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(mcp): preserve calling constraints in compact tool discovery (apache#44656)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat: Add GUI for label_colors in Dashboard Properties Modal (apache#39434)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(opensearch): cover pagination and Content-Type regression against a real instance (apache#44924)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(frontend): finish migrating off direct antd imports, enforce it in custom rules (apache#44927)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(mysql): cover require_mysql_tls fail-closed and verified-TLS paths (apache#44910)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(oracle): cover cancel-query against a real running statement (apache#44908)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* test(cratedb): cover epoch-ms timestamp decoding against a real instance (apache#44904)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(deps): restore dompurify 3.4.16 in frontend lockfile (apache#44960)

* fix(mypy): ignore false-positive union-attr on Slice.uuid.in_() (apache#44944)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* docs(mcp): document semantic-layer MCP tools (apache#44130)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dataset-editor): preserve edits across sort and sync external SQL changes (apache#44858)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(sqlite): write midnight as a bare date for DATE columns in time filters (apache#44805)

Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 25 to 26 (apache#44977)

* chore(deps): bump chromaui/action from 18.7.3 to 18.10.1 (apache#44973)

* chore(deps-dev): bump postcss-styled-syntax from 0.7.2 to 0.7.3 in /superset-frontend (apache#44980)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-frontend (apache#44979)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump webpack-sources from 3.5.3 to 3.6.0 in /superset-frontend (apache#44978)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump chalk from 6.0.0 to 6.0.1 in /superset-frontend (apache#44976)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-embedded-sdk (apache#44974)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-embedded-sdk (apache#44972)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node from 26.6.2 to 26.6.3 in /superset-websocket (apache#44971)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump vitest from 5.0.1 to 5.0.2 in /superset-websocket (apache#44970)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump ws from 8.21.3 to 8.22.0 in /superset-websocket (apache#44969)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore: remove unused INCLUDE_FIREFOX build arg and dead screenshot config (apache#44245)

* fix(explore): preserve pending column configuration edits (apache#44931)

* fix(mcp): return actionable authorized column suggestions (apache#44603)

* chore(deps-dev): bump the swc group in /superset-frontend with 2 updates (apache#44975)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(build): remove unused `polyline` Python dep (apache#44961)

* fix: full CSV download in AgGrid (apache#41696)

Co-authored-by: rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(mcp): support filter_range and filter_timegrain filters (apache#44893)

* fix(models): silence pandas silent-downcasting FutureWarning in normalize_df (apache#44897)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): avoid duplicate SQL execution results (apache#44949)

* fix(charts): return 404 when chart export hits an inaccessible dataset (apache#44900)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): allow bounding dashboard dataset columns (apache#44951)

* feat(mcp): return the Big Number headline from chart and dashboard data (apache#44948)

* fix(logging): stop logging tracebacks for client-side HTTP errors (apache#44666)

* fix(ag-grid-table): refresh totals when summary aggregation changes (apache#44612)

* feat(ci): conditionally run CodeQL analysis workflows only when there are detected JS/Python file changes (apache#44699)

* fix(embedded): refuse guest row-level security on semantic views (apache#44987)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-websocket (apache#45005)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(ag-grid-table): expand JSON values in table cells (apache#44907)

Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* chore(i18n): update pt/pt_BR translations and rebuild translation index (apache#43022)

Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboards): close CSS validation gaps in dashboard import and edits (apache#43666)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(themes): overwrite-import guard, missing index, dedupe extra_editors (follow-up to apache#42404) (apache#44362)

Co-authored-by: Claude Code <noreply@anthropic.com>

* feat(bignumber): add an alignment control (apache#44554)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(reports): propagate force flag to dashboard-tab permalink report URLs (apache#44775)

Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* refactor(list-view): eliminate any usage in ListView.tsx and TableCollection (apache#44208)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(dashboard,explore): wire addWarningToast into download callers (apache#44154)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore(deps): bump the rjsf group in /superset-frontend with 3 updates (apache#45004)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump @swc/core from 1.16.2 to 1.16.12 in /superset-frontend in the swc group (apache#45012)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump @swc/core from 1.16.2 to 1.16.12 in /docs (apache#45008)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /superset-websocket in the security group across 1 directory (apache#45028)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: add global async query playwright tests (apache#43004)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(table): omit dormant grains from semantic aggregate requests (apache#44455)

* fix(semantic-layers): offer valid table ordering choices (apache#44806)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(semantic-layers): remove child view permissions when a layer is deleted (apache#44905)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): bump proxy-addr from 2.0.7 to 2.0.8 in /superset-websocket/utils/client-ws-app in the security group across 1 directory (apache#45027)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump dawidd6/action-download-artifact from 26 to 27 (apache#45011)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /superset-embedded-sdk in the security group across 1 directory (apache#45024)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(pivot-table): respect per-metric formatters in result aggregation (apache#44815)

Co-authored-by: Evan Rusackas <evan@preset.io>

* fix(query-context): match an adhoc granularity_sqla by its expression (apache#44773)

* feat(mcp): allow default values on filter_select native filters (apache#44985)

* feat(mcp): add structured dashboard text component management (apache#44560)

* fix(explore): avoid mutating ZoomConfigControl configs (apache#44957)

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(frontend): await remaining userEvent calls and lint for un-awaited ones (apache#44947)

* fix(explore): open SQL Lab in a new tab on Ctrl+click in View query modal (apache#44933)

* chore(deps): bump the security group across 1 directory with 9 updates (apache#45026)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the security group across 1 directory with 6 updates (apache#45025)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump wait-on from 9.1.0 to 9.4.0 in /superset-frontend (apache#45015)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /superset-frontend (apache#45014)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxlint from 1.85.0 to 1.86.0 in /docs (apache#45009)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the typescript-eslint group in /superset-frontend with 2 updates (apache#45007)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt from 0.70.0 to 0.71.0 in /superset-websocket (apache#45006)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(mcp): support filter-bar dividers in manage_native_filters (apache#45021)

* fix(mcp): state that dataset tools are SQL-only and point to semantic tools (apache#44994)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(dashboards): return 404 when dashboard export hits an inaccessible chart or dataset (apache#44929)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(semantic): add optional metadata refresh SDK contract (apache#44834)

Signed-off-by: Mike Bridge <michael.bridge@preset.io>

* fix(semantic): map layer views as a collection (apache#44902)

* feat(retention): let a host install purge policies for its own soft-delete roots (apache#44892)

* fix(semantic): reject SQL clauses on semantic views (apache#44899)

* fix(security): bind contextual access checks to the datasource type and id (apache#45002)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(permalink): handle concurrent creation of identical dashboard permalinks (apache#45059)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump @types/ws from 8.18.1 to 8.18.2 in /superset-websocket (apache#45045)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the storybook group in /docs with 2 updates (apache#45046)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the storybook group in /superset-frontend with 5 updates (apache#45047)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(post-processing): stop duplicating columns in _append_columns (apache#45018)

* feat(plugin-chart-echarts): add a value axis label control (apache#43660)

* fix(layout): restore growable app shell so injected content above #app doesn't clip it (apache#45056)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat(pivot-table): collapse row groups by default (apache#45030)

* fix(versioning): refuse a chart restore whose datasource no longer exists (apache#44925)

* fix(semantic): hide and ignore series limits that have no series columns (apache#44909)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(async): show the real error for a failed async chart query (apache#45054)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(semantic-layer): show provider queries from chart results (apache#44206)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* perf(security): batch dashboard fallback datasource resolution (apache#44993)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(mcp): refuse changes to externally managed dashboards in all dashboard tools (apache#45062)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(versioning): preserve history across savepoint rollback (apache#45033)

* fix(cache): evict rejected cached GET requests (apache#45055)

* fix(semantic): return a client error for unsupported time grains (apache#45053)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-websocket (apache#45072)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: add DouroECI logo and contributor to In the Wild (apache#45096)

Co-authored-by: José Henrique <jose.teixeira@douroeci.com>

* fix(charts): clear perms of charts whose datasource no longer exists (apache#44926)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(date_parser): use pyparsing snake_case API to silence PyparsingDeprecationWarning (apache#45094)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(mcp): don't page MCP_ERROR_HOOK for user-class errors in the last-resort catch (SC-125493) (apache#45093)

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* feat: SIP-209 Improved Alerts & Reports (apache#44992)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* chore(ci): configure more grouped dep upgrades across npm subprojects  (apache#44696)

Signed-off-by: hainenber <dotronghai96@gmail.com>

* fix(explore): skip Ctrl/Cmd+Enter query while controls have errors or chart is loading (apache#44963)

* fix(explore): show 0 zoom, latitude and longitude in the map view extent tag (apache#44962)

Co-authored-by: Joe Li <joe@preset.io>

* fix(explore): honor a controlled ControlPopover open prop (apache#44959)

* fix(native-filters): show a clear error instead of "Network error" when filter values fail to load (apache#44585)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(explore): dispatch datasource metadata fetch (apache#44958)

* fix(semantic-layer): fail incomplete or unverified semantic query results (apache#44832)

* fix(dashboard): refresh semantic metadata across edits (apache#45052)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* chore: Update CODEOWNERS to include @sadpandajoe (apache#45120)

* feat(mcp): add typed Sunburst chart support (apache#43771)

* fix(semantic-layer): require write access for configuration schema enrichment (apache#45107)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* test(dashboard): wait for async submenu and debounced validation in flaky tests (apache#45106)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>

* fix(datasets): accept certification fields on dataset column and metric PUT (apache#45091)

* chore(deps): bump chromaui/action from 18.10.1 to 18.10.2 (apache#45134)

* fix(semantic-layer): honor provider preferred time dimension (apache#44997)

Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>

* feat(dashboard): add column allowlist to Group By native filter (apache#43736)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* fix(soft-delete): preserve a shared datasource permission on purge (apache#45034)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* perf(versioning): defer capture policy until versioned work (apache#44928)

* fix(date-parser): reject malformed time ranges instead of scanning everything (apache#45098)

* chore(deps-dev): bump wait-on from 9.4.0 to 9.5.1 in /superset-frontend (apache#45048)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps): bump mapbox-gl from 3.31.0 to 3.32.0 in /superset-frontend (apache#45049)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Joe Li <joe@preset.io>

* chore(deps-dev): bump vitest from 5.0.2 to 5.0.3 in /superset-embedded-sdk (apache#45074)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the swc group across 2 directories with 1 update (apache#45118)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump @types/node in /superset-embedded-sdk (apache#45121)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump swagger-ui-react from 5.33.0 to 5.33.1 in /docs (apache#45122)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump yargs from 18.1.0 to 18.2.0 in /superset-frontend (apache#45129)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump oxfmt in /docs (apache#45119)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sepuri Sai Krishna <saik20533@gmail.com>
Co-authored-by: Đỗ Trọng Hải <41283691+hainenber@users.noreply.github.com>
Co-authored-by: Mike Bridge <michael.bridge@preset.io>
Co-authored-by: Joe Li <joe@preset.io>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@rusackas.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Elizabeth Thompson <eschutho@gmail.com>
Co-authored-by: Gaurav Dubey <gauravdubey0107@gmail.com>
Co-authored-by: Gaston Laterza <glaterza@gmail.com>
Co-authored-by: Shaitan <105581038+sha174n@users.noreply.github.com>
Co-authored-by: chadek <32199566+chadek@users.noreply.github.com>
Co-authored-by: 47th <161213233+flcrom@users.noreply.github.com>
Co-authored-by: jayvenn21 <jvennamreddy@gmail.com>
Co-authored-by: Vikash Kumar <163628932+Vikash-Kumar-23@users.noreply.github.com>
Co-authored-by: codeant-ai-for-open-source[bot] <244253245+codeant-ai-for-open-source[bot]@users.noreply.github.com>
Co-authored-by: SBIN2010 <Sbin2010@mail.ru>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Enzo Martellucci <enzomartellucci@gmail.com>
Co-authored-by: mattmc3 <mattmc3@gmail.com>
Co-authored-by: Viktor Högberg <119532259+vhogberg@users.noreply.github.com>
Co-authored-by: Greg Neighbors <gkneighb@mac.com>
Co-authored-by: Greg Neighbors <gregneighbors@Gregs-Air-2.lan>
Co-authored-by: hadi mobarra <53408891+hadimobarra@users.noreply.github.com>
Co-authored-by: Bexultan <bexultan.mustafin@ffins.kz>
Co-authored-by: Archita-kale <kalearchita22@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Mallikarjuna Reddy Nimmakayala <mallikarjunareddy.nimmakayala@gmail.com>
Co-authored-by: Enzo Martellucci <52219496+EnxDev@users.noreply.github.com>
Co-authored-by: Younes Beriane <paranoyouz@gmail.com>
Co-authored-by: Alasdair Brown <sdairs@users.noreply.github.com>
Co-authored-by: Krishna kumar singh <122664891+kksingh000@users.noreply.github.com>
Co-authored-by: Luiz Otavio <45200344+luizotavio32@users.noreply.github.com>
Co-authored-by: Sam Firke <sfirke@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: Dennis Khylkouski <161797777+dennisimoo@users.noreply.github.com>
Co-authored-by: Piyush Raj <piyush.raj2024@nst.rishihood.edu.in>
Co-authored-by: hahaok <35909137+csbbo@users.noreply.github.com>
Co-authored-by: chenshaobo <chenshaobo@yjsafe.cn>
Co-authored-by: Nguyen Dang Trung Tien <trungtien238lnd@gmail.com>
Co-authored-by: Endi Monan <65144790+endimonan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jay Masiwal <masiwaljay.02@gmail.com>
Co-authored-by: Jay Masiwal <jaymasiwal@users.noreply.github.com>
Co-authored-by: Daniel Alyoshin <daniel.alyoshin@gmail.com>
Co-authored-by: Amin Ghadersohi <5183956+aminghadersohi@users.noreply.github.com>
Co-authored-by: Minwook Shin <163576506+minwookshin@users.noreply.github.com>
Co-authored-by: Beto Dealmeida <roberto@dealmeida.net>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
Co-authored-by: Rafael Benitez <rebenitez1802@gmail.com>
Co-authored-by: Israel Demetrios Diacov <66575932+israelddiacov@users.noreply.github.com>
Co-authored-by: Israel Demetrios Diacov <israelddiacov@users.noreply.github.com>
Co-authored-by: Ferjani Nasraoui <ferjani.nasraoui@europace.de>
Co-authored-by: drivaspreset <diego.rivas@preset.io>
Co-authored-by: Abhinav <alpha9coder@gmail.com>
Co-authored-by: Trakshan Mishra <43599000+trakshan-mishra@users.noreply.github.com>
Co-authored-by: Amogh Atreya <amoghatreya100@gmail.com>
Co-authored-by: Divyansh Yadav <anshmcs@gmail.com>
Co-authored-by: Alexandru Soare <37236580+alexandrusoare@users.noreply.github.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: rlei <242280117+rlei-odes@users.noreply.github.com>
Co-authored-by: J0s3-H3nr1qu3 <hareboom@gmail.com>
Co-authored-by: José Henrique <jose.teixeira@douroeci.com>
Co-authored-by: Vitor Avila <96086495+Vitor-Avila@users.noreply.github.com>
Co-authored-by: Mayuri <163738104+mayuriphad@users.noreply.github.com>
Co-authored-by: Mehmet Salih Yavuz <salih.yavuz@proton.me>
villebro pushed a commit that referenced this pull request Oct 9, 2026
)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Mike Bridge <michael.bridge@ext.preset.io>
(cherry picked from commit c30ae9f)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

doc Namespace | Anything related to documentation i18n Namespace | Anything related to localization size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants