Skip to content

feat!: reconcile capability matrix inconsistencies from skill audit - #74

Merged
grdsdev merged 3 commits into
mainfrom
guilherme/sdk-1439-capability-matrix-audit-fixes
Aug 7, 2026
Merged

feat!: reconcile capability matrix inconsistencies from skill audit#74
grdsdev merged 3 commits into
mainfrom
guilherme/sdk-1439-capability-matrix-audit-fixes

Conversation

@grdsdev

@grdsdev grdsdev commented Aug 6, 2026

Copy link
Copy Markdown
Collaborator

Stacked on #73.

Summary

Fixes every finding filed in SDK-1439, the audit produced by running the new capability-matrix skill (#73) against the current matrix.

Breaking (feature ID changes — SDKs' sdk-compliance.yaml referencing the old IDs need updating):

  • storage: merge file_buckets.list_files_paginated into list_files — pagination is now a parameter of one capability, matching the convention already used by vector_buckets/analytics list features
  • storage: split the bundled analytics.iceberg_namespace / iceberg_table IDs into one ID per verb (create/list/delete_namespace, create/list/load/update/rename/delete_table) — matches the per-verb modeling used everywhere else in the file and unblocks per-verb SDK compliance tracking
  • auth: rename sign_in.reset_passwordsign_in.send_password_reset_email to match what it actually does (sends a link; doesn't reset the password itself)
  • realtime: rename channel.sendchannel.broadcast to match its transport twin, channel.broadcast_http

Non-breaking (group reassignment only, IDs unchanged):

  • auth: new mfa_admin group for the two MFA admin ops, mirroring the existing oauth_admin/passkey_admin pattern
  • realtime: presence.presence_keysubscriptions group, alongside the other channel-option features
  • functions: new request_configuration group, mirroring client.yaml/database.yaml's existing config groups
  • database: mutate.select_after_mutationusing_modifiers group (it's a chained modifier, like dry_run, not a mutation verb)

Also added: a platform-scope note on the passkey features, and specs for auth.mfa.enroll, auth.oauth_server.{approve,deny}_authorization, functions.invocation.streaming_response, database.using_modifiers.relationship_embed, and the client third-party-auth / cross-client-token-sync pair (cross-linked).

Declined: renaming the using_filters/using_modifiers group ids to drop their "using_" prefix — cosmetic cross-area style nit, but fixing it would mean renaming ~39 feature IDs. Disproportionate to the finding; left as-is.

Test plan

  • npm run validate — schema + structural checks pass
  • npm test — 183/183 tests pass
  • npm run typecheck — clean
  • Manually reviewed every renamed/split/regrouped ID against its sibling features for the naming/grouping convention it's meant to now match

Adds a repo-local Claude Code skill (.claude/skills/capability-matrix/)
that helps contributors keep capabilities/*.yaml and specs/ internally
consistent: semantic duplicate detection, naming-convention drift within
a group, grouping fit, spec-file suggestions, and platform-scope notes.
It's advisory only and defers to `npm run validate` for anything
mechanical.

Carves out .claude/skills/ from the repo-wide .claude/ gitignore rule so
committed skills are tracked while session/worktree state stays ignored.

Supersedes the CI-bot / PR-review-comment scope in SDK-994.
@grdsdev
grdsdev requested a review from a team as a code owner August 6, 2026 23:10
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@grdsdev, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 51 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: f66f4422-51fd-4317-a84d-4602e07134e5

📥 Commits

Reviewing files that changed from the base of the PR and between 070e2c9 and 891f96c.

📒 Files selected for processing (15)
  • .claude/skills/capability-matrix/SKILL.md
  • .github/workflows/validate-capabilities.yml
  • .gitignore
  • capabilities/auth.yaml
  • capabilities/database.yaml
  • capabilities/functions.yaml
  • capabilities/realtime.yaml
  • capabilities/storage.yaml
  • specs/auth/mfa/enroll.md
  • specs/auth/oauth_server/approve_authorization.md
  • specs/auth/oauth_server/deny_authorization.md
  • specs/client/authentication_integration/cross_client_token_sync.md
  • specs/client/authentication_integration/third_party_auth.md
  • specs/database/using_modifiers/relationship_embed.md
  • specs/functions/invocation/streaming_response.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Two review findings on the capability-matrix skill, both still valid:

- validate-capabilities.yml's PR trigger didn't include specs/**, so a
  spec-only change (e.g. a typo'd path that orphans a spec) could merge
  without ever running the validator that catches exactly that.
- SKILL.md described spec paths as specs/<area>/<group>/<method>.md,
  implying the current `group` field. The directory is actually derived
  from the feature id's own segments (<group_namespace>/<method_stem>
  per the schema), which can now diverge from `group` since SDK-1439
  regrouped several features without renaming their ids. Reworded to
  match the schema's own terminology and call out the divergence.
Base automatically changed from guilherme/sdk-994-llm-skill-for-maintaining-the-capability-matrix to main August 7, 2026 08:17
Addresses the findings filed in SDK-1439 (from the capability-matrix
skill's first full audit):

Breaking (feature ID changes — sdk-compliance.yaml files referencing
the old IDs need updating):
- storage: merge file_buckets.list_files_paginated into list_files
  (pagination is now a parameter of one capability, matching the
  convention already used by vector_buckets/analytics list features)
- storage: split the bundled analytics.iceberg_namespace /
  iceberg_table IDs into one ID per verb (create/list/delete_namespace,
  create/list/load/update/rename/delete_table), matching the per-verb
  modeling used everywhere else in the file and enabling per-verb SDK
  compliance tracking
- auth: rename sign_in.reset_password -> sign_in.send_password_reset_email
  to match what the capability actually does (sends a link, doesn't
  reset the password itself)
- realtime: rename channel.send -> channel.broadcast to match its
  transport twin, channel.broadcast_http

Non-breaking (group reassignment only, IDs unchanged):
- auth: new mfa_admin group for admin.delete_mfa_factor/list_mfa_factors,
  mirroring the existing oauth_admin/passkey_admin pattern
- realtime: presence.presence_key -> subscriptions group, alongside the
  other channel-option features (broadcast_self/ack/replay)
- functions: new request_configuration group for
  region_selection/timeout/request_cancellation/set_auth_token,
  mirroring client.yaml/database.yaml's existing config groups
- database: mutate.select_after_mutation -> using_modifiers group
  (it's a chained modifier, like dry_run, not a mutation verb)

Also adds descriptions/specs for the audit's lighter findings: a
platform-scope note on the passkey features, and new specs for
auth.mfa.enroll, auth.oauth_server.{approve,deny}_authorization,
functions.invocation.streaming_response,
database.using_modifiers.relationship_embed, and the
client.authentication_integration.third_party_auth /
cross_client_token_sync pair (cross-linked via Related).

Declined: renaming the using_filters/using_modifiers group ids to drop
their "using_" prefix (cosmetic cross-area style nit) — the blast
radius (~39 feature ID renames) is disproportionate to the finding.
@grdsdev
grdsdev force-pushed the guilherme/sdk-1439-capability-matrix-audit-fixes branch from 4c87de6 to 891f96c Compare August 7, 2026 08:19
@grdsdev
grdsdev requested a review from a team as a code owner August 7, 2026 08:19
@grdsdev
grdsdev merged commit 9c53a70 into main Aug 7, 2026
5 checks passed
@grdsdev
grdsdev deleted the guilherme/sdk-1439-capability-matrix-audit-fixes branch August 7, 2026 08:48
grdsdev added a commit to supabase-community/supabase-csharp that referenced this pull request Aug 7, 2026
…306)

supabase/sdk#74 renames two feature IDs. Updates references here so
CI's capability compliance validator doesn't fail on unknown IDs:

- auth.sign_in.reset_password -> auth.sign_in.send_password_reset_email
- realtime.channel.send -> realtime.channel.broadcast

This file doesn't currently declare the storage.file_buckets/analytics
IDs also renamed/split in that PR, so nothing else to update here.

No SDK code changes — only the capability declarations. See
supabase/sdk#74 and
https://linear.app/supabase/issue/SDK-1439 for context.
grdsdev added a commit to supabase/supabase-swift that referenced this pull request Aug 7, 2026
…1184)

supabase/sdk#74 renames/splits several feature IDs. Updates references
here so CI's capability compliance validator doesn't fail on unknown IDs:

- auth.sign_in.reset_password -> auth.sign_in.send_password_reset_email
- realtime.channel.send -> realtime.channel.broadcast
- storage.file_buckets.list_files_paginated merged into list_files
- storage.analytics.iceberg_namespace split into create_namespace/list_namespaces/delete_namespace
- storage.analytics.iceberg_table split into create_table/list_tables/load_table/update_table/rename_table/delete_table

No SDK code changes — only the capability declarations. See
supabase/sdk#74 and
https://linear.app/supabase/issue/SDK-1439 for context.
spydon added a commit that referenced this pull request Aug 7, 2026
## Problem

The `symbols` list in `sdk-compliance.yaml` feeds two checks that want
opposite things:

| Check | Reads `symbols` as | Wants |
|---|---|---|
| `checkDrift` | **Evidence** that a capability is implemented | A
short, precise list of entry points, all of which must exist |
| `checkNewSymbols` | **Coverage**, so no new public API slips in
unclassified | An exhaustive account of the entire public surface |

One list cannot serve both. When a capability's supporting types
outnumber its methods, authors get pushed into one of two workarounds:

1. Padding `symbols` with option types, result types and exceptions that
do not implement anything, or
2. Repeating one shared symbol list across several features so each has
something to point at.

Both inflate what the matrix claims is implemented, fan drift warnings
out across features that do not own the symbol, and leave
symbol-to-feature attribution arbitrary, since `buildSymbolIndex`
silently last-wins on collision.

This is not hypothetical. supabase/supabase-flutter#1666 hit it head-on:
reconciling #74 required replicating a 330-symbol Iceberg list across 6
new feature IDs and a 22-symbol list across 3 more, for +1729 lines.
Every one of those 330 symbols now resolves to
`storage.analytics.delete_table` in the symbol index, purely because it
sorts last.

The existing escape hatches do not help. `@internal` and
`.sdk-parse-ignore` remove symbols from the surface entirely, but types
like `TableMetadata` are genuinely public API that consumers construct.
They just are not *capabilities*.

## Change

Adds an optional `supporting_symbols` list, per feature and top level,
that counts for new-symbol coverage and is never drift-verified:

```yaml
storage.analytics.create_table:
  status: implemented
  symbols:
    - IcebergRestCatalog.createTable      # evidence, drift-verified
  supporting_symbols:
    - CreateTableRequest                  # coverage only
supporting_symbols:                       # top level, shared across features
  - IcebergException
```

- `compliance.ts`: new field on `RawValue` and `RawCompliance`;
validation extracted into a shared `checkSymbolList` helper so both
lists get identical treatment; `normalizeCompliance` preserves it;
`buildSymbolIndex` unions both. Entry points are indexed **last**, so a
symbol listed both ways is attributed to the capability that implements
it rather than to a supporting bucket. Top-level entries index against
an exported `TOP_LEVEL_SUPPORTING` sentinel so removal messages stay
readable.
- `drift-check.ts`: **unchanged**. It already read only `value.symbols`,
so the separation falls out for free.
- `api-check.ts`: the failure message now teaches the distinction, since
that message is exactly where an author hits this wall.
- `types.ts`, `docs/capability-matrix.md`, tests.

## Compatibility

The field is optional and the drift check already ignored anything
outside `symbols`, so existing compliance files are unaffected. Verified
that supabase-flutter's current `sdk-compliance.yaml` validates
unchanged.

## Test plan

- [x] 194 tests pass; 12 new, including the two that pin the semantics:
supporting symbols do not satisfy drift on their own, and a missing
supporting symbol produces no drift finding.
- [x] `tsc --noEmit` clean.
- [x] `npm run validate` still OK on the canonical registry.
- [x] Rebuilt supabase-flutter#1666's Iceberg entries in this shape as a
check that it solves the motivating case: 0 drift findings, 0 uncovered
symbols out of 352, attribution exact (`createTable` maps to
`create_table`, not `delete_table`), and **2046 symbol lines become
352**.

## Follow-ups, deliberately not in this PR

- **Reject duplicate symbol registration.** Now that supporting types
have a home this becomes viable, and it would have caught
supabase-flutter#1666's shape automatically. Turning it on today would
fail existing compliance files, so it needs its own migration.
- **`renamed_from` aliases on canonical features.** Separate concern and
arguably higher value: today every ID rename here breaks all seven SDK
repos at once, with no window in which both old and new IDs validate,
because each repo pins the reusable workflow at `@main`.
- **The registry is narrower than the SDKs.** #74 splits namespaces into
create/list/delete, but the real Flutter surface has seven namespace
operations. `loadNamespaceMetadata`, `namespaceExists`,
`updateNamespaceProperties`, `registerTable` and `tableExists` map to no
capability at all. This PR gives them an honest home rather than a false
claim, but the underlying gap is worth deciding on separately.
spydon added a commit to supabase/supabase-flutter that referenced this pull request Aug 7, 2026
…nd splits (#1667)

## Summary

Reconciles `sdk-compliance.yaml` with three upstream changes that have
now landed in `supabase/sdk`:

- **supabase/sdk#74** renamed and split several canonical feature IDs.
- **supabase/sdk#75** separated symbol *evidence* from symbol
*coverage*, adding `supporting_symbols`.
- **supabase/sdk#76** added the five Iceberg catalog capabilities that
#74's split left without an ID.

### Renames and merges

- `auth.sign_in.reset_password` →
`auth.sign_in.send_password_reset_email`
- `realtime.channel.send` → `realtime.channel.broadcast`
- `storage.file_buckets.list_files_paginated` merged into `list_files`
- `storage.analytics.iceberg_namespace` split into `create_namespace` /
`list_namespaces` / `delete_namespace`
- `storage.analytics.iceberg_table` split into `create_table` /
`list_tables` / `load_table` / `update_table` / `rename_table` /
`delete_table`

### New capabilities declared

`load_namespace_metadata`, `namespace_exists`,
`update_namespace_properties`, `register_table`, `table_exists`.

## Why the Iceberg entries look the way they do

Splitting two bundled entries into fifteen raises the question of which
symbols belong where. The Iceberg surface is 352 symbols, only 18 of
which are catalog entry points; the rest are option types, result types,
the schema and type model, and the exception hierarchy.

`symbols` now holds **only** the methods a caller invokes, because the
drift check treats every name in it as evidence the capability exists.
Everything else sits under `supporting_symbols`, which counts for
new-symbol coverage without claiming to implement anything.

Owners for the supporting types are derived from the source rather than
assigned by hand: build the type graph from
`packages/storage_client/lib/src/iceberg/`, including subtype edges
since a signature naming a sealed base reaches every variant a caller
can pass, then ask which entry points reach each type. A type reachable
from exactly one feature belongs to that feature.

| | count |
|---|---|
| Sole natural owner | 37 of 67 |
| Genuinely shared across several features | 20 |
| Reachable from no entry point (thrown, not passed) | 10 |

So all 28 `*Update` and `Assert*` classes land on `update_table`,
`ListTablesOptions`/`ListTablesResult` on `list_tables`,
`RegisterTableRequest` on `register_table`. The schema and type model
and the exception hierarchy stay in the top-level `supporting_symbols`
list, which is the honest answer rather than a coin flip.

The alternative was to replicate the full 330-symbol list across all six
table IDs and the 22-symbol list across all three namespace IDs (+1729
lines, as in the now-closed #1666). That inflates what the file claims
is implemented, fans drift findings across features that do not own the
symbol, and leaves attribution arbitrary, since `buildSymbolIndex`
last-wins on collision. Under that shape only 2 of 9 split features
resolved to their own entry point; here it is 9 of 9.

## Test plan

Validated against current `supabase/sdk@main`, with #74, #75 and #76 all
merged:

- [x] `validate-compliance`: `OK — compliance file is valid.` Two
features remain undeclared (`postgres_changes_multiple_filters`,
`error_codes`); both are pre-existing and out of scope here.
- [x] `check-drift` against symbols extracted with the real Dart
extractor: `✅ No capability matrix drift detected.`
- [x] `check-api-symbols`: all public API accounted for; 887 symbols
covered, unchanged from before this PR.
- [x] Verified no unintended edits: every feature outside the rename and
split scope is byte-identical to `main` after re-serialization.
- [x] CI re-run after the upstream merges: `Validate compliance file`
and `Check public API against capability matrix` both green.

No SDK code changes, only capability declarations.

Context: [SDK-1439](https://linear.app/supabase/issue/SDK-1439)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Standardized capability names for password reset and realtime
broadcast functionality.
* Clarified storage file listing capabilities, including pagination and
sorting support.
* Added more granular capability definitions for Iceberg namespaces and
tables.
* Consolidated shared Iceberg models, errors, catalog access, and
supporting symbols for more consistent capability descriptions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
grdsdev added a commit to supabase/supabase-swift that referenced this pull request Aug 10, 2026
The 5 IDs the sync bot added (auth.sign_in.reset_password,
realtime.channel.send, storage.file_buckets.list_files_paginated,
storage.analytics.iceberg_namespace, storage.analytics.iceberg_table) are
not new — they're the pre-rename names already retired in 450a8fc (#1184)
per supabase/sdk#74.

The bot resynced them because our caller workflow doesn't override the
reusable workflow's sdk-ref input, so it inherits that pinned commit's
baked-in default (faba359a, 2026-07-20), which predates the #74 rename.
Pinning sdk-ref explicitly to a current supabase/sdk main SHA fixes the
root cause.
grdsdev added a commit to supabase/supabase-flutter that referenced this pull request Aug 10, 2026
The 5 IDs the sync bot added (auth.sign_in.reset_password,
realtime.channel.send, storage.file_buckets.list_files_paginated,
storage.analytics.iceberg_namespace, storage.analytics.iceberg_table) are
not new — they're pre-rename names already tracked here under their
current names (send_password_reset_email/broadcast/list_files/the split
namespace and table IDs), per supabase/sdk#74.

The bot resynced them because our caller workflow doesn't override the
reusable workflow's sdk-ref input, so it inherits that pinned commit's
baked-in default (faba359a, 2026-07-20), which predates the #74 rename.
Pinning sdk-ref explicitly to a current supabase/sdk main SHA fixes the
root cause (same fix applied to supabase-swift's equivalent PR #1195).
grdsdev added a commit to supabase/supabase-swift that referenced this pull request Aug 11, 2026
* chore: sync new capability IDs from canonical spec

* chore: drop stale duplicate capability IDs, pin sync to current sdk main

The 5 IDs the sync bot added (auth.sign_in.reset_password,
realtime.channel.send, storage.file_buckets.list_files_paginated,
storage.analytics.iceberg_namespace, storage.analytics.iceberg_table) are
not new — they're the pre-rename names already retired in 450a8fc (#1184)
per supabase/sdk#74.

The bot resynced them because our caller workflow doesn't override the
reusable workflow's sdk-ref input, so it inherits that pinned commit's
baked-in default (faba359a, 2026-07-20), which predates the #74 rename.
Pinning sdk-ref explicitly to a current supabase/sdk main SHA fixes the
root cause.

* ci: track supabase/sdk main for sync-compliance sdk-ref

supabase/sdk is internal (same org, same review process), so treating it
like an untrusted third party by pinning to a SHA isn't buying safety
here. It does cost freshness: the reusable workflow's own baked-in
sdk-ref default is a one-time pin upstream never refreshes, and
supabase/sdk has no tags/releases for anything to key an auto-bump off
of, so a fixed SHA here would just go stale again on its own schedule.
Tracking main avoids that.

* chore: drop explanatory comment from sdk-ref

* ci: bump sync-sdk-compliance pin to the sdk-ref: main fix

supabase/sdk#79 fixes the reusable workflow's own sdk-ref default (was
stuck on the stale faba359a pin since 2026-07-20). Point at that fix
commit directly and drop our local sdk-ref: main override, since it's
now the workflow's default.

Note: 72fda7c is currently on supabase/sdk's unmerged PR #79. Re-pin to
the actual main commit once that merges.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Guilherme Souza <guilherme@supabase.io>
@grdsdev grdsdev mentioned this pull request Aug 12, 2026
3 tasks
grdsdev added a commit that referenced this pull request Aug 12, 2026
## Summary
- The repo has no `v1.0.0` tag/release yet, but #74 (`feat!: reconcile
capability matrix inconsistencies from skill audit`) is a genuine
breaking-change commit. release-please correctly computed a major bump
per Conventional Commits, proposing `2.0.0` for what would be the first
release ever (see PR #81).
- Since nothing has actually shipped, we want the first real release to
be `1.0.0` rather than `2.0.0`.
- Adds `"release-as": "1.0.0"` to `release-please-config.json` to pin
the next release-please PR to `1.0.0`.

## Follow-up
- Once the resulting release-please PR is merged and `v1.0.0` ships,
remove the `release-as` override in a follow-up PR so future releases go
back to normal semver computation.

## Test plan
- [ ] Merge this PR
- [ ] Re-run the `Release` workflow (`workflow_dispatch`) on `main`
- [ ] Confirm the existing release-please PR (#81) updates to target
`1.0.0` instead of `2.0.0`
grdsdev pushed a commit that referenced this pull request Aug 12, 2026
🤖 I have created a release *beep* *boop*
---


## [1.0.0](v1.0.0...v1.0.0)
(2026-08-12)


### ⚠ BREAKING CHANGES

* reconcile capability matrix inconsistencies from skill audit
([#74](#74))

### Features

* add capabilities based on supabase-js public methods
([#19](#19))
([8b07e38](8b07e38))
* add capability-matrix maintenance skill
([#73](#73))
([070e2c9](070e2c9))
* add review-spec and review-spec-compliance skills
([#6](#6))
([b2646c1](b2646c1))
* add SDK implementation status matrix to README and skill
([#4](#4))
([753f06c](753f06c))
* **api-check:** include file path and line number in compliance failure
messages ([#45](#45))
([2f4be47](2f4be47))
* **auth:** add sign-out reason capability
([#47](#47))
([51a3abd](51a3abd))
* canonical SDK capability matrix
([#8](#8))
([215bc3e](215bc3e))
* **capability-matrix:** strict cross-SDK parity score + coverage scope
([#63](#63))
([de1abe1](de1abe1))
* CI check 1 — block PRs adding public API not in capability matrix
([#31](#31))
([293440c](293440c))
* **compliance:** list undeclared features after validation
([#48](#48))
([29f396a](29f396a))
* **compliance:** list undeclared features as notes after validation
([29f396a](29f396a))
* **compliance:** split symbol evidence from symbol coverage
([#75](#75))
([abc8e71](abc8e71))
* initial SDK specs, skills, and install script
([e662b17](e662b17))
* move SDK compliance to per-repo files
([#15](#15))
([4d32675](4d32675))
* **parsers:** add Dart public API parser via package:analyzer
(alternative to [#35](#35))
([#41](#41))
([e3ba07a](e3ba07a))
* **parsers:** add griffe-based Python public API surface parser
([#36](#36))
([c44f836](c44f836))
* **parsers:** replace Swift regex parser with swift-symbolgraph-extract
([#38](#38))
([80529a7](80529a7))
* **realtime:** add multiple postgres_changes filters capability
([#70](#70))
([825ab0c](825ab0c))
* reconcile capability matrix inconsistencies from skill audit
([#74](#74))
([9c53a70](9c53a70))
* rename sdk-parse-ignore to .sdk-parse-ignore
([#37](#37))
([4f4ab61](4f4ab61))
* render symbol names as clickable links in capability matrix
([#14](#14))
([dcaf122](dcaf122))
* show feature description as visible sub-text in capability matrix
([#13](#13))
([3a750ab](3a750ab))
* **site:** serve compliance.json with precomputed parity from GitHub
Pages ([#46](#46))
([0d9106c](0d9106c))
* **storage:** add purge_cache and purge_bucket_cache canonical
capabilities ([#44](#44))
([9a6f864](9a6f864))
* **storage:** add storage.errors.error_codes capability
([#71](#71))
([fabb9a7](fabb9a7))
* **storage:** add the five missing Iceberg catalog capabilities
([#76](#76))
([c3c8f9e](c3c8f9e))


### Bug Fixes

* **aggregate:** point csharp and go SDKs at correct repo slugs
([#62](#62))
([8b7320f](8b7320f))
* **aggregate:** point kotlin SDK at supabase-community/supabase-kt
([#61](#61))
([b1a99e9](b1a99e9))
* **capability-matrix:** correct coverage scope metric description
([#64](#64))
([5daeaf5](5daeaf5))
* **ci:** repair python pipeline and simplify sdk-compliance workflow
([#42](#42))
([2140f44](2140f44))
* **ci:** use nx to run docs:json so workspace deps are built first
([#56](#56))
([9b449bb](9b449bb))
* **dart-extractor:** exclude
[@internal-annotated](https://github.com/internal-annotated) symbols
from the public API surface
([9bd358e](9bd358e))
* **dart-extractor:** exclude [@internal](https://github.com/internal)
symbols from the public API surface
([#54](#54))
([9bd358e](9bd358e))
* remove broken sticky thead, add scroll-margin-top and group-row
borders ([#10](#10))
([68761cd](68761cd))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
grdsdev added a commit that referenced this pull request Aug 12, 2026
## Summary
- Follow-up to #82. The `"release-as": "1.0.0"` override was a one-time
pin to force the first-ever release to `1.0.0` instead of the `2.0.0`
that would otherwise be computed from `#74`'s breaking change.
- `v1.0.0` has now shipped (#81), so this override is removed. Future
releases go back to normal semver computation from commit history.

## Test plan
- [ ] Merge this PR
- [ ] Confirm the next release-please run computes a normal semver bump
(not pinned)
spydon added a commit that referenced this pull request Aug 14, 2026
Adds six capability ids across two areas, plus one new group.

These came out of backfilling supabase-flutter's `sdk-compliance.yaml`
against its full public API
([supabase-flutter#1673](supabase/supabase-flutter#1673)).
Reaching 100% coverage meant every public symbol needed a home, which
made it obvious which operations the registry has no id for. Each one
below is a gap in the registry's own symmetry rather than a Dart-shaped
request: in every case a sibling area already has the equivalent
capability.

## `storage.analytics.access_catalog`

`storage.file_buckets.access_bucket` ("Scope subsequent file operations
to a specific bucket") and `storage.vector_buckets.access_vector_index`
("Scope subsequent vector operations to a specific index within a
bucket") both exist.

Analytics has seventeen operations across namespaces and tables, and no
id for the handle you need before you can call any of them. Worth noting
the asymmetry is recent: #74 and #76 filled in the analytics operations
without adding the accessor the other two groups have.

## `auth.passkey.list_passkeys`, `update_passkey`, `delete_passkey`

`auth.passkey_admin.list_passkeys` and
`auth.passkey_admin.delete_passkey` already cover an admin enumerating
and revoking a user's passkeys. There was nothing for a user managing
their own credentials, which is the more common flow of the two, and no
id at all for renaming one.

`update_passkey` is described narrowly (mutable metadata, such as the
friendly name) since the credential itself is immutable.

## `storage.file_buckets.request_cancellation` and
`storage.configuration.auto_retry`

`database.using_modifiers.request_cancellation` and
`functions.invocation.request_cancellation` both exist, as does
`database.configuration.auto_retry`.

Storage was the one area with retry and abort behaviour and no id for
either, which is arguably backwards: aborting a multi-megabyte upload is
more user-visible than aborting a query. `auto_retry` needs a new
`configuration` group in the storage area, matching the group of the
same name in database.

## What I deliberately left out

Four gaps surfaced in the same audit that I do **not** think belong
here:

- **Client disposal** (`Supabase.instance.dispose`). This started out in
the PR as `client.lifecycle.dispose` and has been dropped following
[review](#78 (comment)).
Two reasons. First, the id was not adjudicable: it needed an escape
hatch so garbage-collected runtimes could declare `not_applicable`, but
process termination releases resources on every runtime, so there was no
observable test separating "reclaims automatically" from "implemented".
Second, the teardown surface a caller can actually see is already
registered, via `realtime.client.disconnect`,
`realtime.client.remove_all_channels` and
`realtime.channel.unsubscribe`. A whole-client `dispose` is largely the
aggregate of those plus internal timers and connection pooling, so its
presence or absence says little about parity that the existing ids do
not already say. Releasing resources idiomatically is a baseline every
SDK owes its framework rather than a feature it can lack.
- **Client construction** (`Supabase.initialize`, `instance`,
`isInitialized`). Every SDK has it, but it is the precondition for the
whole matrix rather than a feature within it.
- **Table streams as a database capability**
(`SupabaseQueryBuilder.stream`). This one is a genuine inconsistency,
but possibly on the Dart side. The registry already carries the
*modifiers* of this capability, since supabase-flutter registers
`SupabaseStreamFilterBuilder.eq` under `database.using_filters.eq` and
`SupabaseStreamBuilder.order` under `database.using_modifiers.order`,
yet there is no id for the operation those modify. supabase-js has no
direct equivalent (you compose a channel with postgres changes by hand),
so this may be Dart sugar that should be attributed differently rather
than a missing id. Raising it as a question rather than proposing an id.
- **Typed row mapping** (`withConverter`). The Dart idiom for what
TypeScript does with generics, so not a cross-SDK capability.

## Compliance impact

None of these is breaking. No id is renamed and no existing entry
changes, so every SDK's `sdk-compliance.yaml` keeps validating; the six
new ids simply default to `not_implemented` until an SDK declares them.

supabase-flutter implements all six and will declare them in a
follow-up, which moves the corresponding symbols out of its generic
top-level `supporting_symbols` list into the features they actually
belong to. Its disposal symbols stay in `supporting_symbols`, which is
where they already are today.

## Test plan

- [x] `npm run validate`: `OK — capability matrix is valid.`
- [x] `npm test`: 195 passed across 14 files.
- [x] `npm run typecheck`: clean.
- [x] Confirmed against `capabilities/*.yaml` that none of the six ids
already exists under another name, and that the new
`storage.configuration` group is new.
- [x] Confirmed `capabilities/client.yaml` is byte-identical to `main`
after dropping the disposal id.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants