Supabase
Category: backend
Monitored sources:
SDK packages:
Last polled: 10/9/2026, 6:00:03 AM
Change History
Four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files copied into their own projects.
10/9/2026
Effective: 12/1/2026
The four framework adapters shipped inside @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files copied into their own projects.
10/7/2026
Effective: 12/1/2026
The four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers should migrate to framework-specific bridge files that compose @supabase/middleware entries instead.
10/7/2026
Effective: 12/1/2026
Four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files that compose @supabase/middleware entries.
10/6/2026
Effective: 12/1/2026
PostgreSQL 15.19/17.11 minor release is being rolled out, requiring potential action for users of ltree indexes, pgcrypto with legacy ciphers (bf/blowfish/cast5), btree_gist indexes on float columns with NaN values, and custom operators with non-built-in selectivity estimators. Additionally, the Supabase Management API `logs.all` analytics endpoint was removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint.
10/5/2026
Effective: 9/28/2026
PostgreSQL 15.19/17.11 minor release is being rolled out, with four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (bf/blowfish/cast5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.
10/5/2026
Effective: 9/28/2026
PostgreSQL 15.19 / 17.11 minor release introduces four potentially breaking changes affecting ltree indexes, pgcrypto legacy ciphers (CVE-2026-14663), btree_gist indexes on float columns with NaN, and custom operators with non-built-in selectivity estimators (CVE-2026-2004). Users must run detection queries and take remediation steps to avoid silent data corruption or future restore failures.
10/2/2026
Effective: 9/28/2026
PostgreSQL minor release 15.19/17.11 introduces four potentially breaking changes affecting ltree indexes, pgcrypto legacy cipher decryption (CVE-2026-14663), btree_gist float indexes, and custom operators with non-built-in selectivity estimators. Affected users must run detection queries and may need to reindex or re-encrypt data.
10/2/2026
Effective: 9/28/2026
PostgreSQL 15.19 / 17.11 minor release introduces four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (Blowfish/CAST5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.
10/1/2026
Effective: 9/28/2026
Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that include four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting data encrypted with legacy ciphers (bf/blowfish/cast5) by default, btree_gist indexes on float columns containing NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.
9/30/2026
Effective: 9/28/2026
Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that introduce four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (blowfish/cast5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.
9/29/2026
Effective: 9/28/2026
Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that include four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (Blowfish/CAST5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and recreating custom operators with non-built-in selectivity estimators now requires superuser. Upgrade available in dashboard from 2026-09-28.
9/28/2026
Effective: 9/28/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, multiple other breaking changes are present including extension version pinning deprecation, Envoy replacing Kong as default API gateway, Realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, and tables no longer auto-exposed to Data/GraphQL API.
9/25/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.
9/23/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23, requiring migration to the new ClickHouse-backed logs endpoint which only accepts ClickHouse SQL. Multiple other breaking changes are also present in this diff, including deprecation of extension version pinning, Envoy replacing Kong as the default API gateway for self-hosted, and Realtime schema lockdown.
9/23/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax.
9/22/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.
9/21/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23, requiring migration to the new ClickHouse-backed `logs` endpoint which accepts ClickHouse SQL only. Multiple other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, Realtime schema lockdown, and several self-hosted configuration changes.
9/20/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, several other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, and tables no longer auto-exposed to the Data/GraphQL API.
9/18/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be replaced with the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. This is one of several breaking changes present in this changelog diff.
9/18/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.
9/17/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.
9/17/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.
9/17/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax.
9/17/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be replaced with the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax. Additionally, multiple other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, realtime schema lockdown, and others.
9/16/2026
Effective: 9/23/2026
Multiple breaking changes are present in this diff, most critically: the Management API `logs.all` analytics endpoint is being removed on 2026-09-23, the Realtime schema is fully locked down against modifications, self-hosted Supabase is switching from Kong to Envoy as the default API gateway, and several other breaking changes affecting auth schemas, Data API exposure defaults, OAuth token response codes, and more.
9/15/2026
Effective: 8/5/2026
Multiple breaking changes are present in this diff, most urgently the removal of the Management API `logs.all` analytics endpoint on 2026-09-23, requiring migration to the new ClickHouse-backed logs endpoint. Additional active breaking changes include: Envoy replacing Kong as the default API gateway for self-hosted (week of 2026-08-09), realtime schema fully locked down, OAuth token endpoint returning HTTP 200 instead of 201, tables no longer auto-exposed to Data/GraphQL API, OpenAPI spec no longer accessible via anon key, and several others.
9/14/2026
Effective: 9/23/2026
The diff contains multiple breaking changes across Supabase's platform, including removal of the `logs.all` analytics endpoint (2026-09-23), deprecation of extension version pinning, Envoy replacing Kong as the default API gateway for self-hosted, Realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, tables no longer auto-exposed to Data/GraphQL API, and several others. The most immediately critical is the `logs.all` endpoint removal on 2026-09-23 and the OpenAPI spec access removal via anon key.
9/14/2026
Multiple breaking changes are present in this changelog, most critically: the Management API `logs.all` analytics endpoint is being removed on 2026-09-23, the Realtime schema is now fully locked down, self-hosted Supabase is switching from Kong to Envoy as the default API gateway, and several other breaking changes affecting Auth, Data API, pg_graphql, and schema permissions are in effect or upcoming.
9/9/2026
Effective: 9/23/2026
The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, multiple other breaking changes are present in this changelog batch, including removal of the `realtime` schema modification access, deprecation of extension version pinning, and Envoy replacing Kong as the default API gateway for self-hosted deployments.
9/8/2026
Effective: 9/23/2026
Get alerts when Supabase changes affect your code
Connect your GitHub repos and Breakwatch will map your Supabase usage and alert you about relevant changes.
Get started for free