From a74fc2ce4bb053aae8c78ea86b71c82e1676b5af Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 20 Jul 2026 01:08:30 +0000 Subject: [PATCH 1/3] chore(deps): bump @supabase/supabase-js from 2.110.2 to 2.110.7 --- updated-dependencies: - dependency-name: "@supabase/supabase-js" dependency-version: 2.110.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- package-lock.json | 80 +++++++++++++++++++++++------------------------ package.json | 2 +- 2 files changed, 41 insertions(+), 41 deletions(-) diff --git a/package-lock.json b/package-lock.json index 6f13cb44e..ed20e33b6 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11,7 +11,7 @@ "dependencies": { "@next/env": "16.2.10", "@supabase/ssr": "^0.12.0", - "@supabase/supabase-js": "^2.108.2", + "@supabase/supabase-js": "^2.110.7", "exceljs": "^4.4.0", "jszip": "^3.10.1", "lucide-react": "^1.22.0", @@ -3286,9 +3286,9 @@ "license": "MIT" }, "node_modules/@supabase/auth-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/auth-js/-/auth-js-2.110.2.tgz", - "integrity": "sha512-Qj7a6EDP+AMMQFWqGv+qFa8r6re//dk+qQI5bA0KK+PZmnI3JPu97TDeNt6SMiQ2FkklP79hP2yDFYSnA989OA==", + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/auth-js/-/auth-js-2.110.7.tgz", + "integrity": "sha512-M5Bpl4hCv6kHcOO/xM06Dyfg1mYLHljMkp1plhzG9IRZPc3czvyMsSN1XpL5+GKisOKM3lSN59zhpcm6sMVXfA==", "license": "MIT", "dependencies": { "tslib": "2.8.1" @@ -3298,9 +3298,9 @@ } }, "node_modules/@supabase/functions-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/functions-js/-/functions-js-2.110.2.tgz", - "integrity": "sha512-ZjjqrXpxM9/rE+eAtZxiK45EWy9EBoJQ322Q5Y75LccYQNh212neHTgXP/o4MIzmH0LNXT8UzvTZtQOfOzyoeQ==", + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/functions-js/-/functions-js-2.110.7.tgz", + "integrity": "sha512-megYmexlYEoR/0qlsr4Snh9wtzAodO7MAri3NMevZrXzNvQRKlvmTcSBoKGLQEPDakgDZMqbMdf9DwoZz6qfoA==", "license": "MIT", "dependencies": { "tslib": "2.8.1" @@ -3309,12 +3309,31 @@ "node": ">=22.0.0" } }, + "node_modules/@supabase/phoenix": { + "version": "0.4.5", + "resolved": "https://registry.npmjs.org/@supabase/phoenix/-/phoenix-0.4.5.tgz", + "integrity": "sha512-aAn9H9ovVyeApKy11OWOrrOGq8DV68yWeH4ud2lN9fzn4aO8Zb5GLL9m1pUg9nLqIcT+ZDfAcsZe0E/nqdv2lw==", + "license": "MIT" + }, "node_modules/@supabase/postgrest-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/postgrest-js/-/postgrest-js-2.110.2.tgz", - "integrity": "sha512-++LBmcIMwCtgO4tISQUmo9+2xkRwHQqS8ZKMCnhXLe9P8k8YQRXuMoh/RiSzQSoev8gqet0W7yOboW0cUxnt0Q==", + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/postgrest-js/-/postgrest-js-2.110.7.tgz", + "integrity": "sha512-ban6YV0djhVaqVYezlOARKLIuOBSvLLhyQVZjA2nxPrtswhxHCl1+gI4giFgI9ATQAaMNbUZb4JXiuL5lEA/5g==", + "license": "MIT", + "dependencies": { + "tslib": "2.8.1" + }, + "engines": { + "node": ">=22.0.0" + } + }, + "node_modules/@supabase/realtime-js": { + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/realtime-js/-/realtime-js-2.110.7.tgz", + "integrity": "sha512-AMtZjyFA2gsmjuxopPNS/sRznLQHG0Ht5x+ytTPTOh3vAcOTUlVRLx7gW4/CONNnbb3PKOkE+HmM35HOSbmomQ==", "license": "MIT", "dependencies": { + "@supabase/phoenix": "0.4.5", "tslib": "2.8.1" }, "engines": { @@ -3334,9 +3353,9 @@ } }, "node_modules/@supabase/storage-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/storage-js/-/storage-js-2.110.2.tgz", - "integrity": "sha512-EhsRSwSnmQefKJsAxoRUZ0hvHr92ECM8DDGAKR5z0HdoJx4heI60PjHUTruVNZxKX6XeobLGDyLud020Bw1iwg==", + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/storage-js/-/storage-js-2.110.7.tgz", + "integrity": "sha512-2tcDE8cjEDy1uKxKavBpKQod1JdMV1jDXQag48TCa+kycmJOltc0yVabC0BUlhOwAl6WykXU2aOsH3ELMtZrmQ==", "license": "MIT", "dependencies": { "iceberg-js": "^0.8.1", @@ -3347,35 +3366,16 @@ } }, "node_modules/@supabase/supabase-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/supabase-js/-/supabase-js-2.110.2.tgz", - "integrity": "sha512-r9q9w4ZQ6mOjh36aqUNFSisBF611vzpO8JphBESr2Q1SWvmGFQeI7Jq7Y+PaNMZ6Zszz+S2yTlJStCpnaMSnQg==", + "version": "2.110.7", + "resolved": "https://registry.npmjs.org/@supabase/supabase-js/-/supabase-js-2.110.7.tgz", + "integrity": "sha512-AnfO3A230Shy6RMO7cya3Wl1OcXnABJrzH8vP+fY7/RFjhzcchB7DjKkkTIAntlwekD+GkSFzEvt2tC+D4Fp8w==", "license": "MIT", "dependencies": { - "@supabase/auth-js": "2.110.2", - "@supabase/functions-js": "2.110.2", - "@supabase/postgrest-js": "2.110.2", - "@supabase/realtime-js": "2.110.2", - "@supabase/storage-js": "2.110.2" - }, - "engines": { - "node": ">=22.0.0" - } - }, - "node_modules/@supabase/supabase-js/node_modules/@supabase/phoenix": { - "version": "0.4.4", - "resolved": "https://registry.npmjs.org/@supabase/phoenix/-/phoenix-0.4.4.tgz", - "integrity": "sha512-Gt0pqoXuIqX/8dvG0OKp/wMCobXNH3klNbUPBNyOfN0YA1IswrM3HyWFMOPk1Jy+BRaIyDPcFx4jLBwHNmlyfQ==", - "license": "MIT" - }, - "node_modules/@supabase/supabase-js/node_modules/@supabase/realtime-js": { - "version": "2.110.2", - "resolved": "https://registry.npmjs.org/@supabase/realtime-js/-/realtime-js-2.110.2.tgz", - "integrity": "sha512-z3jTOTPgyn6E3r6dVOOQ10He4yAMB2czjFw7xVdX3s16MHElna5rY1gVaePs0NIo6xvtMYbtmOXlFaFt/ePLpg==", - "license": "MIT", - "dependencies": { - "@supabase/phoenix": "0.4.4", - "tslib": "2.8.1" + "@supabase/auth-js": "2.110.7", + "@supabase/functions-js": "2.110.7", + "@supabase/postgrest-js": "2.110.7", + "@supabase/realtime-js": "2.110.7", + "@supabase/storage-js": "2.110.7" }, "engines": { "node": ">=22.0.0" diff --git a/package.json b/package.json index fad4fa8c0..ac3d007a9 100644 --- a/package.json +++ b/package.json @@ -177,7 +177,7 @@ "dependencies": { "@next/env": "16.2.10", "@supabase/ssr": "^0.12.0", - "@supabase/supabase-js": "^2.108.2", + "@supabase/supabase-js": "^2.110.7", "exceljs": "^4.4.0", "jszip": "^3.10.1", "lucide-react": "^1.22.0", From 155942f43547f80a9f7767178fc12c8818b3f159 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Mon, 20 Jul 2026 16:41:13 +0800 Subject: [PATCH 2/3] =?UTF-8?q?=F0=9F=94=A7=20CodeRabbit=20CI=20Fix:=20Fix?= =?UTF-8?q?=20failing=20GitHub=20Actions=20Docker=20and=20CI=20checks=20(#?= =?UTF-8?q?970)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --- scripts/check-client-bundle-secrets.mjs | 15 ++++++++++----- tests/client-secret-surface.test.ts | 17 +++++++++++++++++ 2 files changed, 27 insertions(+), 5 deletions(-) diff --git a/scripts/check-client-bundle-secrets.mjs b/scripts/check-client-bundle-secrets.mjs index 9319a103f..a007ab333 100644 --- a/scripts/check-client-bundle-secrets.mjs +++ b/scripts/check-client-bundle-secrets.mjs @@ -11,9 +11,12 @@ const forbiddenMarkers = [ "OPENAI_ORG_ID", "OPENAI_PROJECT_ID", "RAG_QUERY_HASH_SECRET", - "sb_secret_", - "sk-proj-", - "sk-svcacct-", + // Match an actual key value (prefix + key body), not a bare prefix-check + // string literal. @supabase/supabase-js ships `key.startsWith('sb_secret_')` + // client-side as of 2.110.x, which would otherwise be a false positive here. + /sb_secret_[A-Za-z0-9]/, + /sk-proj-[A-Za-z0-9]/, + /sk-svcacct-[A-Za-z0-9]/, ]; function textFiles(root) { @@ -47,9 +50,11 @@ const offenders = new Map(); for (const file of [...textFiles(publicRoot), ...textFiles(clientBuildRoot)]) { const content = readFileSync(file, "utf8"); for (const marker of forbiddenMarkers) { - if (content.includes(marker)) { + const matched = marker instanceof RegExp ? marker.test(content) : content.includes(marker); + if (matched) { + const markerLabel = marker instanceof RegExp ? marker.source : marker; const relativePath = relative(projectRoot, file).replaceAll("\\", "/"); - offenders.set(`${relativePath}\0${marker}`, { marker, relativePath }); + offenders.set(`${relativePath}\0${markerLabel}`, { marker: markerLabel, relativePath }); } } } diff --git a/tests/client-secret-surface.test.ts b/tests/client-secret-surface.test.ts index 9db8dcf02..8f911214c 100644 --- a/tests/client-secret-surface.test.ts +++ b/tests/client-secret-surface.test.ts @@ -169,6 +169,23 @@ describe("client environment isolation", () => { expect(publicResult.status).toBe(1); expect(publicResult.stderr).toContain("public/unsafe.txt"); expect(publicResult.stderr).toContain("SUPABASE_SERVICE_ROLE_KEY"); + + rmSync(join(fixtureRoot, "public", "unsafe.txt")); + // @supabase/supabase-js ships a bare `key.startsWith('sb_secret_')` prefix + // check client-side; that literal alone must not trip the scanner. + writeFileSync( + join(staticRoot, "sdk-prefix-check.js"), + "const isNewApiKey = (key) => key.startsWith(\"sb_publishable_\") || key.startsWith(\"sb_secret_\");", + "utf8", + ); + const prefixOnlyResult = spawnSync(process.execPath, [scannerPath], { cwd: fixtureRoot, encoding: "utf8" }); + expect(prefixOnlyResult.status).toBe(0); + + rmSync(join(staticRoot, "sdk-prefix-check.js")); + writeFileSync(join(staticRoot, "leaked-key.js"), "const key = 'sb_secret_abc123DEF456';", "utf8"); + const leakedKeyResult = spawnSync(process.execPath, [scannerPath], { cwd: fixtureRoot, encoding: "utf8" }); + expect(leakedKeyResult.status).toBe(1); + expect(leakedKeyResult.stderr).toContain(".next/static/leaked-key.js"); } finally { rmSync(fixtureRoot, { recursive: true, force: true }); } From 5fb48a24aeed4977e871a40bae6186039e6bca68 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Mon, 20 Jul 2026 17:43:48 +0800 Subject: [PATCH 3/3] =?UTF-8?q?=F0=9F=94=A7=20CodeRabbit=20CI=20Fix:=20Fix?= =?UTF-8?q?=20Static=20PR=20Checks=20and=20Gitleaks=20CI=20Failures=20(#97?= =?UTF-8?q?8)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> --- tests/client-secret-surface.test.ts | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/tests/client-secret-surface.test.ts b/tests/client-secret-surface.test.ts index 8f911214c..6274bac46 100644 --- a/tests/client-secret-surface.test.ts +++ b/tests/client-secret-surface.test.ts @@ -175,14 +175,18 @@ describe("client environment isolation", () => { // check client-side; that literal alone must not trip the scanner. writeFileSync( join(staticRoot, "sdk-prefix-check.js"), - "const isNewApiKey = (key) => key.startsWith(\"sb_publishable_\") || key.startsWith(\"sb_secret_\");", + 'const isNewApiKey = (key) => key.startsWith("sb_publishable_") || key.startsWith("sb_secret_");', "utf8", ); const prefixOnlyResult = spawnSync(process.execPath, [scannerPath], { cwd: fixtureRoot, encoding: "utf8" }); expect(prefixOnlyResult.status).toBe(0); rmSync(join(staticRoot, "sdk-prefix-check.js")); - writeFileSync(join(staticRoot, "leaked-key.js"), "const key = 'sb_secret_abc123DEF456';", "utf8"); + // Built via concatenation so this fixture's synthetic, non-functional key + // never appears as a contiguous literal in this test's own source (which + // would otherwise look like a real leaked secret to git secret scanners). + const fakeSecretKey = ["sb_secret_", "abc123DEF456"].join(""); + writeFileSync(join(staticRoot, "leaked-key.js"), `const key = '${fakeSecretKey}';`, "utf8"); const leakedKeyResult = spawnSync(process.execPath, [scannerPath], { cwd: fixtureRoot, encoding: "utf8" }); expect(leakedKeyResult.status).toBe(1); expect(leakedKeyResult.stderr).toContain(".next/static/leaked-key.js");