---
name: Serverless Postgres
slug: serverless-postgres
description: Managed Postgres with scale-to-zero and branching for modern stacks.
member_count: 5
canonical: https://releases.sh/collections/serverless-postgres
---

# Serverless Postgres

Managed Postgres with scale-to-zero and branching for modern stacks.

## Members (5)

- [Neon](https://releases.sh/neon) — neon.tech
- [Supabase](https://releases.sh/supabase) — supabase.com
- [PlanetScale](https://releases.sh/planetscale) — planetscale.com
- [Turso](https://releases.sh/turso) — turso.tech
- [Prisma](https://releases.sh/prisma) — prisma.io

## Fetching more

Append `.md` (markdown), `.json` (raw data), or `.atom` (feed) to any URL on this page.

- Aggregated release feed: `https://releases.sh/collections/serverless-postgres.atom`
- Weekly digests: `https://releases.sh/collections/serverless-postgres/digest.atom`

## Recent Releases

---
collection: serverless-postgres
collection_name: Serverless Postgres
release_count: 20
has_more: true
canonical: https://releases.sh/collections/serverless-postgres
---

<Release version="v0.300.0" date="July 14, 2026" published="2026-07-14T01:06:45.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.300.0" org="planetscale" source="planetscale-cli">
## Changelog
* 3b582551bbfb73436beeaf01e44b1a05c043fe23 Add test guarding against reintroducing planetscale-go
* 1eb0099eefc3299095f3612e27b491237f0cf582 Add workflow mirroring the client back to planetscale-go
* 7ada02e074b4b947fb28247d5915e65178b37e0c Document the vendored API client for agents and contributors.
* 5838b9c423bee2ca109986b591c839be38e71598 Fetch tags in planetscale-go checkout so gorelease finds its base
* 0d1f4ede674c4f83d3a93c7b3327243948fdf5c5 Fix import grouping after the client import path rewrite (go fmt).
* 97b128d45b67e1ad54134c200b58987186e2df34 Improve role reassign invalid ID guidance
* f616b4f9779912b2b75da0dca8d507566736dab6 Keep internal API endpoints out of the planetscale-go mirror
* cc14ba6bfa717604f764a44218adb7129cf45e76 Merge branch 'main' into remove-planetscale-go-dependancy
* adee0bda79d043ac162f1ab5590f478f630a939e Merge main: global-keyspace move-tables works against the vendored client
* 320acc190ea0b437630da366c5fc03dfa282383d Merge origin/main (postgres role with-replication) into the vendored-client branch.
* fe792c991725f30d144727ce7e35b01beb2e3633 Merge remote branch (main merged, includes d1 sqlite3 fix)
* 89bc30a50af5d17323c057f68db6ba08fd46b359 Promote go-humanize to a direct dependency (used by branch infra output).
* f96daec48a78d88aefe1db009364e7d00e37b542 Remove temporary push trigger now that the sync workflow is verified
* c21deca346de766971ba4ba5feb5c9b9f52830e7 Rename mirror workflow and script to sync-planetscale-go
* a973291f89fe648e7ee759b03cd4a8d3efda3286 Restore upstream client.go so the vendored copy is byte-identical
* 2c893ad839c131768a4f804522e0a6a25006dd52 Retrigger CI.
* b8364d8ae627da5ff53a7fc2c9045ccdb85424b3 Run mirror job in the release environment for app credentials
* 81724b66b3c82e9970c364957473cf51c058212b Skip deployment records for the sync job's environment use
* 9c2f6d1e36ace1c6dcfe0518d354304895ffa82f Sync the vendored client to planetscale-go v0.176.0.
* a453e9dda80be1a379cc249e4bf8c3dcb83fe467 Sync the vendored client to planetscale-go v0.178.0 and merge main.
* 63882ee2b7f481b16c1c33882f05000e9738d3c6 Temporarily trigger mirror workflow on branch push for testing
* 821ffa1e2059249c68596abd84c091670fe6c054 Use the CLI GitHub App for mirror auth
* 281fa922d04407edc762f2381786635c69d3e885 Vendor the API client from planetscale-go into internal/planetscale.
* 45158e548724c1741c2b66ed781e59d5d46a00a5 fix(release): darwin/amd64 binaries abort on macOS 26


</Release>

<Release version="v2.193.0" date="July 13, 2026" published="2026-07-13T18:37:05.000Z" url="https://github.com/supabase/auth/releases/tag/v2.193.0" org="supabase" source="supabase-auth">
## [2.193.0](https://github.com/supabase/auth/compare/v2.192.0...v2.193.0) (2026-07-07)


### Features

* **linking:** add experimental provider linking-domain groups ([#2604](https://github.com/supabase/auth/issues/2604)) ([c4f6964](https://github.com/supabase/auth/commit/c4f69649a0d95a86648b23657795b5430894f472))


### Bug Fixes

* downgrade session AAL after admin deletion of factor ([#2607](https://github.com/supabase/auth/issues/2607)) ([4d1d660](https://github.com/supabase/auth/commit/4d1d660674ce15d9858cc220a3deda0cf0088077))
* **mfa:** use AMR method (not factor type) when downgrading sessions to AAL1 ([#2615](https://github.com/supabase/auth/issues/2615)) ([dfe62d0](https://github.com/supabase/auth/commit/dfe62d0fcc047099614c2eaff4b4d20d807671d9))

## Checksums
### SHA1
`auth-v2.193.0-arm64.tar.gz`:
```
631e0e4f4d1ef58bd532a27fe3ba4743d02d7b30
```

`auth-v2.193.0-darwin-arm64.tar.gz`:
```
bddfcaf167e58558fc442fd0a2142ef2e84fd136
```

`auth-v2.193.0-x86.tar.gz`:
```
e0790fd029afe16247505507e8307a58f9a852bd
```

`auth-v2.193.0-amd64.tar.xz`:
```
f04c2496bda3f4b1cd13e3206c045aa689fc595d
```

`auth-v2.193.0-arm64.tar.xz`:
```
47d94c70e7d0e39911c5c29d9fa384ad3ecfcce7
```

### SHA256
`auth-v2.193.0-arm64.tar.gz`:
```
1fcf0874066d87097cfde758359da626b55b15b31a83f49347afc9299da2542e
```

`auth-v2.193.0-darwin-arm64.tar.gz`:
```
d52fe458263917db1def5180ebd54d989bea0073c01e4d93395351f9f2d25575
```

`auth-v2.193.0-x86.tar.gz`:
```
69f70343082e310ade768c573616d6f998213b583a3aa8a8a7a79a11935eabfc
```

`auth-v2.193.0-amd64.tar.xz`:
```
c991b6fb8747bbcbcef40701177234f152cea28a108a481bae917bacc1a522c5
```

`auth-v2.193.0-arm64.tar.xz`:
```
432fa68ef58afac8665d45537d8adbba5756b01829f175ed7ef6314b3ca59995
```
</Release>

<Release version="v0.7.0" date="July 13, 2026" published="2026-07-13T15:39:39.000Z" url="https://github.com/tursodatabase/turso/releases/tag/v0.7.0" org="turso" source="turso">
## 0.7.0 -- 2026-07-13

## Release Notes

### Added

* core/mvcc: add passive checkpoint (Pere Diaz Bou)
* dotnet: support NativeAOT static native linking (Marc-André Moreau)
* core/alloc: add stable push_within_capacity helper (Pedro Muniz)
* core/storage: add savepoint rollback consistency intent (Pekka Enberg)
* Add some testing guidance for agents (Pekka Enberg)
* Add Aristo WAL verification (Sushant Dinesh)
* add artificial wait for sticky disk to have latest snapshot (Pedro Muniz)
* sync/engine: add missing fsync() (Nikita Sivukhin)
* Add Windows ARM64 CLI release support (Marc-André Moreau)
* Add .NET remote transactions and batches (Marc-André Moreau)
* Add .NET remote Hrana execution (Marc-André Moreau)
* Add Turso EF Core SQLite provider (Marc-André Moreau)
* mvcc: Add fallible MVCC row payload allocation sites (Pedro Muniz)
* Add mobile NuGet native targets (Marc-André Moreau)
* core: register additional virtual tables into the catalog (Glauber Costa)
* alloc: add specialization in nightly for Vec (Pedro Muniz)
* core/alloc: Add allocation site annotations and out-of-memory fault injector (Pedro Muniz)
* mvcc: lazily resolve shadow in new IndexShadowFinger (Preston Thorpe)
* mvcc: add allocator generic to mv store (Pedro Muniz)
* Add SQL-standard scalar functions and PG-compatible aliases (Glauber Costa)
* Add shared buffer views for serialization callbacks (Pedro Muniz)
* Reject `ALTER TABLE ADD COLUM` when generated-columns flag is off (Vartan Babayan)
* add win tests for db/sync on js (Nikita Sivukhin)
* Add .NET NuGet package publishing workflow (Marc-André Moreau)
* mvcc: add sequence_watermark function and track sequence allocations (Preston Thorpe)
* Refactor memory benchmark into library + add CodSpeed CI tracking (Pedro Muniz)
* core/skiplist: use TursoAllocator for node allocation and add fallible inserts (Pedro Muniz)
* serverless/javascript: add option for custom request headers (Nikita Sivukhin)
* add yielding IO back-end for turso-stress to test async re-entrancy (Preston Thorpe)
* python: enable Tantivy FTS and add tests (Pekka Enberg)
* feat: add PostgreSQL-style sequences and MVCC-safe AUTOINCREMENT (Glauber Costa)
* core/storage: Only mark WAL initialized after a successful header sync (Pekka Enberg)
* core/mvcc: avoid SeekingToLast with MVCC in newrowid (Pere Diaz Bou)
* Window functions plumbing 1: add stubs for builtins, refactor row_number() to use VDBE aggregate machinery (Jussi Saurio)
* core/translate: support FILTER in window clauses (Jussi Saurio)
* Add mvcc recovery benchmark (Mikaël Francoeur)
* core: Add WITHIN GROUP ordered-set aggregates (Glauber Costa)
* Add recovery-heavy profile to Whopper (Mikaël Francoeur)
* Introduce portable logical log metadata for turso sync (Preston Thorpe)
* Add regression test for incorrect OR expression handling (Pavan Nambi)
* core/io: add runtime-registrable Rust IO backend (Robert Sturla)
* extensions: add macro for context-scalar functions (Preston Thorpe)
* Add core custom collation support (Marc-André Moreau)
* Add managed aggregate callback support (Marc-André Moreau)
* core/mvcc: set read_set to Vec and add batch query read bench (Pere Diaz Bou)
* Add managed scalar callback foundation (Marc-André Moreau)
* core/mvcc: add MVCC recovery regression cases (Avinash Sajjanshetty)
* COMPAT.MD: fix errors, be more precise, add turso-specific PRAGMAs (Jussi Saurio)
* Support UPSERT targets on partial indexes (Pedro Muniz)
* agent: add yield injections skill (Avinash Sajjanshetty)
* core/mvcc: Add per-connection extension loading (Marc-André Moreau)
* core/translate/optimizer: support non-equijoin FULL OUTER JOIN (russell romney)
* introduce ImmutableRecordRef to reduce cloning (Mikaël Francoeur)
* Add locale-backed collations to Turso (Aziz Batihk)
* Add SQLite-compatible .NET bindings (Marc-André Moreau)
* Add Database.batch() method to JavaScript SDKs (Pekka Enberg)
* simulator: support virtual columns (Mikaël Francoeur)
* Add allocator API for fallible allocation (Pedro Muniz)
* bindings/javascript: Add concurrent transaction support (Pekka Enberg)
* Add section on AI coding to CONTRIBUTING.md (Pekka Enberg)
* apply virtual gen-col affinity in OLD probe and NEW key (Mikaël Francoeur)

### Updated

* core: reject co-enablement of MVCC and multiprocess WAL (Jussi Saurio)
* core/translate: use abort journal analysis for upsert DO UPDATE arms (roboturso)
* build(deps): bump js-yaml from 4.1.0 to 4.3.0 in /bindings/javascript (app/dependabot)
* build(deps): bump ws in /examples/react-native (app/dependabot)
* Eliminate blocking I/O in page cache spill path (Nikita Sivukhin)
* build(deps): bump shell-quote from 1.8.3 to 1.10.0 in /examples/react-native (app/dependabot)
* core/json: coerce numeric JSONB aggregate object labels to strings (Hossam Khero)
* Drop the beta warning (Glauber Costa)
* core/btree: invalidate shape caches on peer writes; drop trigger workaround (Glauber Costa)
* core: disallow multiple write stmts in single connection and poison tx if half-done write stmt is abandoned (Jussi Saurio)
* bindings/js: serialize wasm native calls against sync-engine worker tasks (Jussi Saurio)
* testing/stress: reset shuttle step counter on iteration progress (Jussi Saurio)
* Page cache soft limit (Jussi Saurio)
* core/mvcc: mark recovery delete tombstones for truncated frames btree-resident (Mikaël Francoeur)
* core: make schema cloning fallible (Pedro Muniz)
* schema: make sqlite_schema bootstrap allocation fallible (Pedro Muniz)
* schema: make generated column graph allocation fallible (Pedro Muniz)
* Mvcc sync (Preston Thorpe)
* core/wal: prevent stale checkpoint backfill publish (Avinash Sajjanshetty)
* core/mvcc: reset index shadow finger when index keys are created mid-scan (roboturso)
* core/storage: capture savepoint WAL position during write_tx upgrade after acquiring write lock (Jussi Saurio)
* core/mvcc: finish live-version rewrite when a committed commit statement is dropped (roboturso)
* core: classify virtual tables by parsing schema SQL (roboturso)
* core/mvcc: keep exact-seek short-circuit for b-tree-only rows (roboturso)
* bump fossier dependency to allow for vouch command (Preston Thorpe)
* core/alloc: clone Vec elements through TryClone (Pedro Muniz)
* core: fsync WAL when raw frame insert session force-commits (Pekka Enberg)
* fossier: vouch for @roboturso (Preston Thorpe)
* core/translate: use try_push for create table column Vec (Pedro Muniz)
* core/vdbe: make vec allocations fallible (Pedro Muniz)
* core/translate: propagate fallible Vec allocations (Pedro Muniz)
* core/btree: clear abandoned B-tree overflow cells (Avinash Sajjanshetty)
* github: skip dotnet code signing on non-main branches (Pekka Enberg)
* core/storage: Remove checkpoint leak intent (Pekka Enberg)
* bindings/rust: break sync io worker retention cycle (Pekka Enberg)
* sqlite/parser: bound expression depth to prevent translator stack overflow (roboturso)
* github: drop sccache from workflows (Pekka Enberg)
* perf(vdbe): reuse btree cursor on OpenRead instead of rebuilding (Glauber Costa")
* perf(vdbe): reuse btree cursor on OpenRead instead of rebuilding (Glauber Costa)
* propagate push/pull thresholds to the python and golang SDK (Nikita Sivukhin)
* perf(vdbe): only build the comparator and clone the aggregate arg when needed (Glauber Costa)
* stress: use bare RNG methods (Mikaël Francoeur)
* core/vdbe: avoid overflow when cache_size is i32::MIN (roboturso)
* core/optimizer: improve starting table selection in greedy join (Akira Noda)
* core/pager: reset pager state on savepoint rollback (Pedro Muniz)
* Python bindings cleanup (Mikaël Francoeur)
* python: release the GIL and expose interrupt() / set_query_timeout() (Glauber Costa)
* core/mvcc:  preserve B-tree cleanup markers in MVCC commit logs (Avinash Sajjanshetty)
* Delete memory benchmark artifact after run (Pedro Muniz)
* antithesis: squash targeting diff into targeted_coverage.json (Mikaël Francoeur)
* Bump concurrent-ruby from 1.3.3 to 1.3.7 in /examples/react-native (app/dependabot)
* core: allow deterministic date functions in generated columns (Artur Kantorczyk)
* core: allow custom allocator for MVStore (Pedro Muniz)
* refresh mvcc schema for checkpoint state machine when it acquires checkpoint lock (Jussi Saurio)
* Clarify in CONTRIBUTING.md that mold linker is Linux only (n3on p0rtal)
* github: code-sign Windows artifacts with Azure Artifact Signing (Pekka Enberg)
* Update references from limbo to turso in docs (n3on p0rtal)
* Exercise MVCC recovery in turso_stress (v2) (Mikaël Francoeur)
* antithesis diff-focused tests (Mikaël Francoeur)
* core/mvcc: retain ended btree_resident row versions till checkpoint (Avinash Sajjanshetty)
* Revert "core/mvcc: use per-MvStore skiplist collectors" (Pedro Muniz)
* core/mvcc: use per-MvStore skiplist collectors (Pedro Muniz)
* core/wal: do not mark dirty pages clean during WAL cacheflush (Avinash Sajjanshetty)
* Linear better than quadratic (Nikita Sivukhin)
* Move SQLite C API to bindings/c (Pekka Enberg)
* ci: Gate CodSpeed shards on matching build (Pedro Muniz)
* Move SQLite parser to `sqlite/parser` directory (Pekka Enberg)
* core: More blocking I/O removal (Preston Thorpe)
* core/btree: prevent leaking pinned pages in page stack (Preston Thorpe)
* sync: Use core allocator Vec in sync engine for compile reasons (Pedro Muniz)
* conformance/javascript: cover big integer round-trip with safe integers (Pekka Enberg)
* Eliminate quadratic performance for prepare of queries with a lot of parameters (Nikita Sivukhin)
* Track MVCC checkpoint allocation sites (Pedro Muniz)
* ci: shard CodSpeed benchmarks by toolchain and benchmark (Pedro Muniz)
* core: remove info instruments that can become verbose (Pere Diaz Bou)
* mvcc: use fallible skiplist allocations (Pedro Muniz)
* mvcc: decouple GC from checkpointing and make configurable (Preston Thorpe)
* avoid full range scan for index seek operation (Nikita Sivukhin)
* javascript: Return per-statement results from batch() (Pekka Enberg)
* Experimental features sync sdk (Nikita Sivukhin)
* mvcc: merge-iterate the index during forward btree scans (Pere Diaz Bou)
* core/mvcc: reuse record (Pere Diaz Bou)
* Revert single-pass recovery (Mikaël Francoeur)
* Make durable storage log completion awaitable (Pedro Muniz)
* core/translate: SQLite-compatible affinity check for index seeks (Jussi Saurio)
* Update to PyO3 0.29.0 (Pekka Enberg)
* Single-pass MVCC recovery (Mikaël Francoeur")
* mvcc: some memory use improvements (Preston Thorpe)
* simulator: dont rollback simulator connection level transaction state for create table failure (Preston Thorpe)
* core, sdk-kit: ColumnTypeInfo for custom-type-aware column metadata (Glauber Costa)
* mem usage in MVCC: pack timestamp begin/end in RowVersion (Preston Thorpe)
* core/mvcc: RowKey::Record set to Arc (Pere Diaz Bou)
* core: make the nightly allocator cfg build green and gate it in CI (Pedro Muniz)
* core/translate: Improve DDL compatibility with SQLite (Glauber Costa)
* Step result yield (Nikita Sivukhin)
* core/mvcc: Shrink version chains and remove empty slots at checkpoint (Pedro Muniz)
* logs: lower level for spam INFO logs (Nikita Sivukhin)
* core/skiplist: re-vendor crossbeam-skiplist from upstream main (Pedro Muniz)
* core: vendor crossbeam-skiplist 0.1.3 as core/skiplist module (Pedro Muniz)
* build(deps-dev): bump shell-quote from 1.8.3 to 1.8.4 in /bindings/react-native (app/dependabot)
* perf/connection: regenerate stale limbo lockfile to drop git2 (Pekka Enberg)
* build(deps-dev): bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.7 in /bindings/react-native (app/dependabot)
* core/mvcc: checkpoint must use the schema of the database it operates on (Glauber Costa)
* Remove blocking IO from mvcc bootstrap and recovery paths (Preston Thorpe)
* lock cargo-fuzz to 0.13.0 to prevent CI failure (Preston Thorpe)
* build(deps): bump ws from 8.20.0 to 8.21.0 in /testing/conformance/javascript (app/dependabot)
* Preserve JS row positional values (Pedro Muniz)
* core/mvcc: Call checkpoint hooks during bootstrap recovery (Pedro Muniz)
* Discuss "can I work on it" in CONTRIBUTING.md (Pekka Enberg)
* core/translate: preserve declaration order when nesting window subqueries (Jussi Saurio)
* feat: REINDEX (Jussi Saurio)
* core/vdbe: Make scalar function edge cases SQLite compatible (Ben Zaid)
* core/schema: Migrate code to use fallible collect (Pedro Muniz)
* core/numeric: Coerce text exceeding i64::MAX to Float, not saturated int (Jussi Saurio)
* github: Use Blacksmith build-push action for simulator image build (Pekka Enberg)
* core/mvcc: allow custom durable storage for encrypted MVCC (Avinash Sajjanshetty)
* core/translate: case-insensitive NATURAL JOIN and USING column lookup (Jussi Saurio)
* Update devcontainer (Mikaël Francoeur)
* move runtime check to compile time (Mikaël Francoeur)
* Single-pass MVCC recovery (Mikaël Francoeur)
* do not rollback attached pagers on reprepare if the conn is inside transaction (Pedro Muniz)
* Expose managed extension APIs through SDK-kit and .NET bindings (Marc-André Moreau)
* core/mvcc: prevent stale tx from acquiring `exclusive_tx` after concurrent commit (Avinash Sajjanshetty)
* Rollback temp schema when dropping MVCC commit (Mikaël Francoeur)
* Bump idna from 3.11 to 3.15 (app/dependabot)
* bindings/rust: replace hyper-tls with hyper-rustls (PlumJam)
* Pin cargo-c to 0.10.16 due to rust-toolchain.toml being pegged at 1.88 (Yinka Makanjuola)
* core/mvcc: skip seeking on contigous writes to pager (Pere Diaz Bou)
* Bump openssl from 0.10.79 to 0.10.80 (app/dependabot)
* core/mvcc: store rowversion chain in mvcc iterator (Pere Diaz Bou)
* Begin to remove all blocking IO from core (Preston Thorpe)
* Rework Dockerfiles to use a `.dockerignore` (Mikaël Francoeur)
* core/mvcc: preempt checkpoint while collecting rows to write_set (Pere Diaz Bou)
* impl `try_from_iter` for `Box<[T]>` (Pedro Muniz)
* Remove StreamingLogicalLogReader::next_record (Mikaël Francoeur)
* refactor `Extendable` trait to use Result for fallible allocations (Pedro Muniz)
* migrate `hash_table.rs` to use fallible Vec (Pedro Muniz)
* migrate `sorter.rs` to use fallible vec allocations (Pedro Muniz)
* migrate `order_by.rs` to use fallible vec allocations (Pedro Muniz)
* convert `expr_walk*` to use iteration instead of recursion (Pedro Muniz)
* core/mvcc: serialize buffer directly, avoid 2x buffer heap size (Pere Diaz Bou)
* core: raise recursion_limit to 256 for FromRepr on Insn (Glauber Costa)
* core/mvcc: Guard global_header write against out-of-order commits (Glauber Costa)
* core/mvcc: Rollback MVCC tx after commit conflicts with SchemaConflict (Jussi Saurio)
* core/mvcc: Skip transient view and trigger deletes during MVCC checkpoint (Jussi Saurio)
* Gate custom benchmark iterations for CodSpeed (Pedro Muniz)
* revert: make all fallible functions use current infallible methods for now (Pedro Muniz)
* core/mvcc: make MVCC integrity_check reprepare after checkpoint root publication (Avinash Sajjanshetty)
* bindings/python: enable PyO3 abi3-py310 for a single cross-version wheel (Pekka Enberg)
* core/mvcc: rollback savepoint on abandoned statement (Pere Diaz Bou)
* core: enable percentile extension by default (Preston Thorpe)
* github: Bump turso_whopper regression-test step timeout to 15 minutes (Pekka Enberg)
* github: Use Playwright container for wasm browser tests (Pekka Enberg)
* core/functions: Allow whitespace in datetime() arguments (HoangTechCS | AIE")
* tests/integration: Verify source MVCC log exists before `VACUUM INTO` (Vartan Babayan)
* core/functions: Allow whitespace in datetime() arguments (HoangTechCS | AIE)
* core/vdbe: Preserve blob bytes when casting to BLOB (Karina)
* core/mvcc: check schema cookie during get_commit_timestamp (Pere Diaz Bou)
* Only rollback if auto commit is true (Rohith Suresh)
* bindings/js/sync: bump concurrent-actions-consistency timeout to 30s (Pekka Enberg)
* sqlite3: Respect `n_byte` length in `sqlite3_prepare_{v2,v3}` (Tommy Williams)
* chore: rename project from "Limbo" to "Turso" (Nikolai Grlica)
* core/alter: Clear sqlite_sequence after removing AUTOINCREMENT (Nyasha Hama)
* core: invalidate deferred seek in op_seek_rowid (Mikaël Francoeur)
* Feature/6444 pragma vdbe trace (H)
* Do not reject delete_from sqlite_sequence incorrectly (Rohith Suresh)
* github: Bump `test-limbo` timeout to 30 minutes (Pekka Enberg)
* Github actions cleanups (Pekka Enberg)
* core: open with absolute path (Pere Diaz Bou)
* sdk-kit: clarify crates.io descriptions point Rust users to `turso` (Pekka Enberg)
* core/mvcc: preserve rowid allocator watermark (Avinash Sajjanshetty)
* build(deps): bump urllib3 from 2.6.3 to 2.7.0 (app/dependabot)
* core/printf: return NULL for empty format (oska)
* bindings/rust: Disable test_sync_parallel_writes_with_sync_ops test case (Pekka Enberg)
* core/schema: Preserve AUTOINCREMENT after DROP COLUMN (Nyasha Hama)
* core/mvcc: yield on big serialization of transaction (Pere Diaz Bou)
* Rollback abandoned MVCC commits on cleanup (Mikaël Francoeur)

### Fixed

* Fix unsafe concurrent BTreeMap use in memory IO backends (Jussi Saurio)
* core/translate: report qualified column refs in ALTER TABLE trigger errors (roboturso)
* core/function: resolve jsonb_replace to its jsonb variant (LucasArray)
* core/json: fix UTF-8 corruption in JSON5 string serialization (Prathamesh Anvekar)
* github: Fix Windows release build and signing failures (Pekka Enberg)
* sync: fix race between concurrent opens of the same synced replica (Glauber Costa)
* fix file lock of WAL for multiprocess opens (Preston Thorpe)
* fix/sync: Replay pushed CREATE DDL with IF NOT EXISTS (Jussi Saurio)
* Fix various corruption issues (Jussi Saurio)
* simulator: fix dropping rows from improperly rolled back connection (Preston Thorpe)
* remove debug code (Pedro Muniz)
* core/function: resolve jsonb_patch in function name lookup (LucasArray)
* core: Fix uuid_str() and uuid_blob() on nullable columns (Preston Thorpe)
* Fix cdc mode empty txn (Nikita Sivukhin)
* bump fossier dependency to fix vouch command (Preston Thorpe)
* stress: handle integrity check error correctly (Mikaël Francoeur)
* Fix Antithesis targeted coverage output format to JSONL (Mikaël Francoeur)
* docs: Fix time extension types (Pekka Enberg)
* change error message for fallible allocations (Pedro Muniz)
* ci: fix codspeed runs being treated separately (Pedro Muniz)
* fix nonblocking read_page race and wal frame cache slot reuse corruption (Preston Thorpe)
* fix duplicate rowid allocation in cdc instructions v2 emission (Preston Thorpe)
* Fix WAL spill frame reuse during page spills (Pedro Muniz)
* fix(pragma): silently ignore unknown PRAGMA names (Chris Siddall)
* github: fix Windows codesign repack, use 7z instead of zip (Pekka Enberg)
* Fix .NET SQLite facade compatibility (Marc-André Moreau)
* core/translate: Fix NULL parent-key semantics in FK parent checks (Pavan Nambi)
* json: fix json_set panics on array append (Artur Kantorczyk)
* Fix README.md: invalid Go syntax and double .db file extension (n3on p0rtal)
* fix(schema): store bare trigger target table name on schema reload (Glauber Costa)
* core/mvcc: fix requires_seek on mvcc checkpoint insert (Pere Diaz Bou)
* core/translate: Fix partial index predicate consumption (Jussi Saurio)
* core/mvcc: properly complete checkpoint in case of error (Nikita Sivukhin)
* Resolve cargo artifact dir via scripts/cargo-target-dir (Pekka Enberg)
* fix test_normalize_ident: impl was changed, test was not (Jussi Saurio)
* fix correlated subquery inside aggregate with GROUP BY (Darko)
* core/translate: Fix ordinal ORDER BY and GROUP BY with COLLATE (Yassine Elyaakoub)
* fix: materialize DELETE rowset when FK cascade triggers back to target (Jussi Saurio)
* fix: spurious sqlite_stat1 NULL-idx rows emitted by ANALYZE (Jussi Saurio)
* fix: handle rowid-alias columns in composite FK key probes (Pavan Nambi)
* core/vdbe: Fix AVG() for text values with numeric prefixes (Hossam Khero)
* core/translate: nest FROM-clause subquery coroutine bodies to fix hash join bugs (Jussi Saurio)
* extensions/fuzzy: Fix index out of bounds panic in fuzzy string (Danawan Bimantoro)
* core/mvcc: fix deadlock on impl Display for Transaction (Pere Diaz Bou)
* fix: Invalid `changes()` Count When CDC Is Enabled (Akira Noda)
* serverless/javascript: Fix stack overflow error with large blobs (Henry)
* core/translate: Fix affinity of compound subquery result columns (Glauber Costa)
* fix: avoid CDC overwriting last insert rowid (Akira Noda)
* javascript: Fix Database.inTransaction property (Pekka Enberg)
* Fix recursive FK cascades causing stack overflow (Jussi Saurio)
* return error instead of panic on invalid type conversion (Nikita Sivukhin)
* propagate `IndexInfo` allocation error (Pedro Muniz)
* Propagate immutable record allocation errors (Pedro Muniz)
* Fix ignored updates and self-referential updates incorrectly mutating FK violation counters (Jussi Saurio)
* optimizer: fix two FULL OUTER JOIN planner bugs (Preston Thorpe)
* Fix for VACUUM INTO panic on nested statement yields (ISSUE #7237) (Benjamin Ebby)
* testing/simulator: fix drop index accounting in query profile (Pekka Enberg)
* Fix MVCC schema recovery for frame-level index ops (Jussi Saurio)
* Convert `BitSet` and callers that use it to propagate fallible allocation errors (Pedro Muniz)
* fix: align AUTOINCREMENT seq coercion with SQLite (Kumar Ujjawal)
* Fix DROP COLUMN expression index metadata (ReV)
* fix cargo fmt complaints (Avinash Sajjanshetty)
* core/mvcc: fix MVCC checkpoint duplicate index entries for interior index keys (Avinash Sajjanshetty)

## Install turso_cli 0.7.0

### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-installer.sh | sh
```

### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-installer.ps1 | iex"
```

## Download turso_cli 0.7.0

|  File  | Platform | Checksum |
|--------|----------|----------|
| [turso_cli-aarch64-apple-darwin.tar.xz](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-apple-darwin.tar.xz) | Apple Silicon macOS | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-apple-darwin.tar.xz.sha256) |
| [turso_cli-x86_64-apple-darwin.tar.xz](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-apple-darwin.tar.xz) | Intel macOS | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-apple-darwin.tar.xz.sha256) |
| [turso_cli-aarch64-pc-windows-msvc.zip](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-pc-windows-msvc.zip) | ARM64 Windows | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-pc-windows-msvc.zip.sha256) |
| [turso_cli-x86_64-pc-windows-msvc.zip](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-pc-windows-msvc.zip) | x64 Windows | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-pc-windows-msvc.zip.sha256) |
| [turso_cli-aarch64-unknown-linux-gnu.tar.xz](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-unknown-linux-gnu.tar.xz) | ARM64 Linux | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-aarch64-unknown-linux-gnu.tar.xz.sha256) |
| [turso_cli-x86_64-unknown-linux-gnu.tar.xz](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-unknown-linux-gnu.tar.xz) | x64 Linux | [checksum](https://github.com/tursodatabase/turso/releases/download/v0.7.0/turso_cli-x86_64-unknown-linux-gnu.tar.xz.sha256) |

## Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):
```sh
gh attestation verify <file-path of downloaded artifact> --repo tursodatabase/turso
```

You can also download the attestation from [GitHub](https://github.com/tursodatabase/turso/attestations) and verify against that directly:
```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```



</Release>

<Release version="v2.110.3" date="July 13, 2026" published="2026-07-13T12:30:32.000Z" url="https://github.com/supabase/supabase-js/releases/tag/v2.110.3" org="supabase" source="supabase-js">
## 2.110.3 (2026-07-13)

### 🩹 Fixes

- **auth:** preserve pkce verifier ([#2513](https://github.com/supabase/supabase-js/pull/2513))
- **postgrest:** pin tstyche target off floating latest ([#2509](https://github.com/supabase/supabase-js/pull/2509))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
- Vaibhav @7ttp
</Release>

<Release date="July 10, 2026" published="2026-07-10T00:00:00.000Z" url="https://neon.com/docs/changelog/2026-07-10" org="neon" source="neon-changelog">
## A new neon api CLI command, Cmd+K in the Console, and more release - Jul 10, 2026

## Jul 10, 2026– A new neon api CLI command, Cmd+K in the Console, and more

## New`neon api`command in the Neon CLI

The Neon CLI now ships an [`api`](/docs/cli/api) command: call any [Neon Platform API](/docs/reference/api) route from the terminal using your existing CLI login, without hand-building `curl` requests or giving agents raw API keys.

Dedicated CLI commands cover common workflows, but the Platform API moves faster. With the `neon api` command, you get full API reach the moment an endpoint exists. Run `neon api --list` to browse every route from the OpenAPI spec.

[Read the announcement](https://neon.com/blog/introducing-neon-api-command) for why we built this for agent workflows.

List projects for your organization:

```
neon orgs list
neon api /projects -Q org_id=org-cool-darkness-12345678
```

Create a dev branch on an existing project:

```
neon api /projects/late-frost-12345678/branches -X POST -F branch.name=dev
```

The `-F branch.name=dev` flag builds the JSON body `{ "branch": { "name": "dev" } }` automatically. See the [`api` command reference](/docs/cli/api) for query parameters, file bodies (`-d @file`), and output formats.

## Cmd+K support for the Neon Console

You can now press `Cmd+K` (Mac) or `Ctrl+K` (Windows/Linux) from anywhere in the Neon Console to open a searchable command bar with actions scoped to your current branch and project: navigate to branches, open the SQL editor, create a snapshot, go to settings, and more.

![Neon Console command bar](/docs/changelog/command_k.png?dpl=dpl_FjCNkFQhwbGhuQm26LXRjo8Vavrb)

## Neon MCP Server: branch expiration on create

The [Neon MCP Server](/docs/ai/neon-mcp-server) `create_branch` tool now accepts an optional `expiresAt` parameter (ISO 8601) to set automatic branch deletion when creating a branch, matching the Neon API and console Auto-delete behavior. See [branch expiration](/docs/guides/branch-expiration).

Connect the MCP Server in your editor:

```
npx add-mcp https://mcp.neon.tech/mcp
```

For full setup (API key auth, agent skills, and more), run `npx neon@latest init`. See [Connect MCP clients to Neon](/docs/ai/connect-mcp-clients-to-neon).

## New NAT gateway IPs and VPC endpoint services in US East (Ohio), Europe (London), and Asia Pacific (Singapore)

We've expanded infrastructure capacity in the AWS US East (Ohio) (`us-east-2`), Europe (London) (`eu-west-2`), and Asia Pacific (Singapore) (`ap-southeast-1`) regions with new NAT gateway IP addresses and new VPC endpoint service addresses for Private Networking.

#### Update your IP allowlists

If you have IP allowlists on external systems that Neon connects to, **update those allowlists to include the new NAT gateway addresses**. Connections may be affected intermittently if traffic routes through non-allowlisted NAT gateways.

If you use Private Networking in these regions, you can now use the additional VPC endpoint service addresses for enhanced capacity and reliability. See the [Regions documentation](/docs/introduction/regions#aws-nat-gateway-ip-addresses) for the complete list of NAT gateway IPs and the [Private Networking guide](/docs/guides/neon-private-networking) for VPC endpoint service addresses by region.

## Postgres turns 30

Postgres turned 30 on July 8. [See our post on X](https://x.com/neondatabase/status/2074892704115470796).

Neon is a long-term bet on Postgres. We support Postgres 14 through 18 today, with Postgres 19 support on the way. Our team includes Postgres hackers who [contribute upstream](https://neon.com/blog/postgres-18) and support the wider ecosystem through our [Open Source Program](https://neon.com/blog/neon-open-source-program). We run standard Postgres, not a fork: [Neon is Postgres](/docs/reference/compatibility), with serverless branching and autoscaling built around the database millions of developers already rely on.

Happy birthday, Postgres. 🎂🐘
</Release>

<Release version="v1.26.07" date="July 9, 2026" published="2026-07-09T21:13:24.000Z" url="https://github.com/supabase/supabase/releases/tag/v1.26.07" org="supabase" source="supabase">
## Developer Update - July 2026

Here's everything that happened with Supabase in the last month:

## OpenCode integrates with Supabase

<img width="1200" height="630" alt="opencode-thumb" src="https://github.com/user-attachments/assets/4649228d-56e6-4d1b-a9bf-c84cbd2b95f2" />

OpenCode connects your agent to your Supabase database, Edge Functions, and logs. It configures the MCP setup for you.

[Read the blog →](https://supabase.com/blog/agentic-coding-on-supabase-with-opencode)

## TanStack DB syncs with Supabase

<img width="1200" height="630" alt="tanstack" src="https://github.com/user-attachments/assets/4d2d7894-e7a7-491e-ae77-b7507207a6a2" />

`@supabase-labs/tanstack-db` syncs TanStack DB collections with your Supabase tables over PostgREST and Realtime. It's available in alpha.

[Watch the demo →](https://x.com/supabase/status/2069429278253498562)

## Wrappers adds a MongoDB foreign data wrapper

<img width="1200" height="630" alt="querymongodbwrapper" src="https://github.com/user-attachments/assets/2c77a20b-85af-42cf-bbf9-137d79d6d379" />

Wrappers v0.6.2 lets you query and join MongoDB collections directly from Postgres. It also fixes OpenAPI FDW pagination.

[Read the docs →](https://supabase.com/docs/guides/database/extensions/wrappers/mongodb)

## Multigres supports LISTEN/NOTIFY across pooled connections

<img width="1200" height="630" alt="multigreslistennotify" src="https://github.com/user-attachments/assets/29b5fbe6-4a34-481d-83bb-5c64338f3cbc" />

Multigres keeps Postgres LISTEN/NOTIFY working even when connections are pooled away from clients.

[Read the blog →](https://multigres.com/blog/2026-05-24-listen-notify)

## Realtime Broadcast supports binary payloads

<img width="1200" height="630" alt="binarypayloads" src="https://github.com/user-attachments/assets/f61fca26-3584-4cdc-b909-cb81cf5a0c0c" />

Realtime Broadcast now sends and receives binary payloads in addition to JSON. Binary payloads cut encoding overhead for cases like sensor telemetry and live screenshot streaming.

The Dart, Kotlin, and Python clients don't support binary payloads yet, and older SDK versions silently drop them. Update your client before you rely on it.

[Read the docs →](https://supabase.com/docs/guides/realtime/broadcast)

## Quick Product Announcements

- Postgres `log_connections` now defaults to off for new projects on all tiers as of July 9, and existing Free and Pro projects are being migrated to the new default. [[GitHub Discussion](https://github.com/orgs/supabase/discussions/47197)]
- `pg_graphql` v1.6.2 ships with GraphQL schema introspection off by default, so enable it per schema if you use GraphiQL or codegen tools. [[GitHub Discussion](https://github.com/orgs/supabase/discussions/46320)]
- Audit Log Drains are available, so you can stream your project's audit logs to an external destination. [[Docs](https://supabase.com/docs/guides/security/platform-audit-logs#accessing-audit-log-drains)]
- Connect copies every environment variable `@supabase/server` needs in a single click. [[Demo](https://x.com/softwarecuddler/status/2067649901811609655)]
- Self-hosted Docker defaults changed: `API_EXTERNAL_URL` now includes the `/auth/v1` prefix, and the default image moves to Postgres 17. [[GitHub Discussion](https://github.com/orgs/supabase/discussions/47093)]

## Meet the Supabase team

- **Supabase Live:** Building high quality Supabase apps using TRAE. July 22 at 7 pm PT. [[Register](https://supabase.com/events/supabase-trae-high-quality-apps)]
- Supabase x Claude Community Meetup in Dublin. [[Register](https://luma.com/dublin-8-2026-07-meetup)]
- Hangout with the Supabase team during Casual Wednesdays on Discord at 10:00 am PT. [[Join](https://discord.supabase.com/)]

## Made with Supabase

- Shapeships: A multiplayer browser game using simultaneous-turn mechanics, built on an authoritative Supabase backend. [[Website](https://shapeships.juddmadden.com/)]
- Blind OS: An autonomous outreach and client-management system that finds leads, qualifies them, and follows up on payments. [[Website](https://blindos.co)]
- rlsautotest: Generates pgTAP tests and seed data from your Supabase RLS policies to prove, per table and identity, who can read or write which rows. [[GitHub](https://github.com/unitautogen/rlsautotest)] [[PyPI](https://pypi.org/project/rlsautotest/)]
- Heym: An open-source visual AI workflow automation platform with a native Supabase node for querying and mutating tables through PostgREST. [[GitHub](https://github.com/heymrun/heym)]

## Community Highlights

- A practical security checklist for non-technical builders, with Row Level Security flagged as the single most important fix. [[Read](https://javieroch.substack.com/p/the-vibe-coders-survival-guide-what)]
- A transparent cost breakdown for a personal life-management system built with Claude Code and Supabase, plus an honest look at the security tradeoffs of self-hosting your own data. [[Read](https://jeradhill.substack.com/p/what-it-actually-costs-to-run-my)]
- A widely-shared guide to vibecoding with Claude Code positions Supabase as the default data layer and login system in its standard setup flow. [[Read](https://ruben.substack.com/p/the-claude-code-bible)]
</Release>

<Release version="v0.299.0" date="July 9, 2026" published="2026-07-09T19:48:15.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.299.0" org="planetscale" source="planetscale-cli">
## Changelog
* c64b47bb746b2ab546bed8f289a9f78b8c65c7db Add --global-keyspace to branch vtctld move-tables create
* 2dcc8eca344f00a5a95be20e5648668b65da023a Bump planetscale-go to v0.178.0
* 36fcb112f52c41572a39d49a70d3ebf41b20d399 Isolate d1 import sqlite3 runs from user config


</Release>

<Release version="v2.110.2" date="July 9, 2026" published="2026-07-09T10:58:42.000Z" url="https://github.com/supabase/supabase-js/releases/tag/v2.110.2" org="supabase" source="supabase-js">
## 2.110.2 (2026-07-09)

### 🩹 Fixes

- **auth:** clear local session on signout failures ([#2504](https://github.com/supabase/supabase-js/pull/2504))

### ❤️ Thank You

- Luc Peng
</Release>

<Release date="July 9, 2026" published="2026-07-09T10:00:00.000Z" url="https://neon.com/blog/introducing-neon-api-command" org="neon" source="neon-blog">
## Introducing the New Neon API Command

# Introducing the New Neon API Command

The Neon CLI now ships an `api` passthrough command that gives your agent every Neon API endpoint the moment it exists.

![Introducing the New Neon API Command](https://cdn.neonapi.io/public/images/pages/blog/introducing-neon-api-command/cover.jpg)

CLIs in many ways have become the default tool of choice for AI agents. And this is for good reason. They package complex environments into predictable, bite-sized commands that agents can parse and execute reliably.

But CLIs also have a problem. They're optimized for human developer experience. To make life easier for a human engineer, a CLI often combines multiple API endpoints into a single command, hiding the underlying complexity. This abstraction is great for humans, but it creates a significant problem for an autonomous agent: **feature lag**.

Because human-centric CLIs require intentional design and manual updates, they naturally lag behind the core API surface area. If an agent is leveraging a standard CLI, it's restricted to a subset of features. In exchange for a streamlined human DX, you sacrifice the speed and granularity that an agent needs.

## Why not just call the API directly?

It's a fair question. Hitting raw endpoints solves the feature-lag issue — but agents are notoriously error-prone when working with an API directly. Namely, they often struggle with authentication and secret management.

Making direct, authenticated API calls requires an agent to locate, insert, and handle access tokens manually. This introduces frequent points of failure and risks inadvertently leaking high-privilege tokens into shell history files, application logs, or the agent's own conversational memory.

## The new Neon API command

To bridge this gap, we've added the `api` command to the [Neon CLI](https://neon.com/docs/reference/neon-cli). This command serves as an escape hatch that gives your agent the raw power of the [Neon API](https://neon.com/docs/reference/api-reference) paired with the local guardrails of the CLI.

The moment a new endpoint is added to the Neon API, your agent can access it natively through the terminal. For example, to list your projects, an agent can simply run:

```
neon api /projects -Q org_id={org_id}
```

Or, if it needs to spin up a new branch with specific configurations:

```
neon api /projects/{id}/branches -X POST -F branch.name=dev
```

The CLI seamlessly maps flags to core HTTP primitives exactly as you would expect:

- `-X` explicitly sets the HTTP method.
- `-F key=value` builds a typed JSON body with dot-notation nesting (e.g. `-F branch.name=dev` → `{ "branch": { "name": "dev" } }`).
- `-Q` appends query parameters.
- `-H` injects custom headers.
- `-d @file` / `-d -` reads a request body directly from a file or stdin.

## The best of both worlds

By routing raw API calls through the CLI, you get true credential isolation. Authentication is handled seamlessly in the background by the local CLI environment, which means your agent never has to touch or manage raw secrets, eliminating the risk of token leaks.

Additionally, agents don't have to guess what operations are available to them or scrape outdated documentation to find new endpoints. They can simply run:

```
neon api --list
```

This returns a complete, up-to-date manifest of available endpoints right in their terminal session.

With the updated Neon CLI, agents no longer have to compromise between the safety of a CLI and the full velocity of the Neon API.

## Our inspiration

It's important to call out that we didn't invent this pattern from scratch. We borrowed a phenomenal one from our partners at Vercel. Their open-source CLI ships an authenticated [`api` command](https://vercel.com/docs/cli/api) built on this exact philosophy, which we adapted to handle Neon's nested JSON payloads.

## Try it out

Curated commands make a CLI pleasant. A passthrough command makes it complete. For agents, complete is what unblocks them, and doing it through the CLI's own auth is what keeps it safe.

If you're building tools for agents, this is a cheap, high-leverage pattern: wrap your API with an authenticated, spec-aware passthrough so nothing is ever out of reach, and so tomorrow's endpoints work today.

Try it now:

```
npm i -g neon
```

Package: [`neon` on npm](https://www.npmjs.com/package/neon).
</Release>

<Release version="v0.178.0" date="July 9, 2026" published="2026-07-09T08:52:51.000Z" url="https://github.com/planetscale/planetscale-go/releases/tag/v0.178.0" org="planetscale" source="planetscale-go-sdk">
## What's Changed
* Add GlobalKeyspace to MoveTablesCreateRequest by @mcrauwel in https://github.com/planetscale/planetscale-go/pull/322


**Full Changelog**: https://github.com/planetscale/planetscale-go/compare/v0.177.0...v0.178.0
</Release>

<Release date="July 9, 2026" published="2026-07-09T07:00:00.000Z" url="https://supabase.com/blog/searchable-field-level-encryption-with-cipherstash" org="supabase" source="supabase-changelog">
## Searchable field-level encryption on Supabase with CipherStash

The [CipherStash integration](https://supabase.com/partners/integrations/cipherstash?utm_source=supabase_announcement_post&utm_medium=blog&utm_campaign=launch) for Supabase is now available.

[CipherStash](https://cipherstash.com/?utm_source=supabase_announcement_post&utm_medium=blog&utm_campaign=launch) is a Data Level Access Control (DLAC) platform for applications built on Postgres. DLAC extends traditional access control, which typically operates at the row or table level, down to individual encrypted values, so policies are enforced at decryption rather than at the query layer.

With CipherStash, teams can encrypt sensitive fields at the application layer with a unique key per value, run searches and joins against encrypted data without decrypting it, and keep keys under their own control through ZeroKMS, CipherStash's zero-knowledge key management service. Because keys never leave your control, neither CipherStash nor Supabase can access your plaintext data.

The Supabase integration enables teams to add field-level encryption to any Supabase project using the encrypted Supabase SDK wrapper without changing the schema. Setup is one CLI command: `npx stash init --supabase`.

[Video](https://www.youtube-nocookie.com/embed/SHa7XTeHYK8)

## Why this matters for regulated workloads#

Most teams that handle regulated data end up choosing between two bad options:

1. **Use traditional field-level encryption:** Encrypted values are random bytes as far as Postgres is concerned. `WHERE email = ?` matches nothing, indexes stop working, and joins fail. The only way to search is to pull every row, decrypt it in your app, and filter in memory. Teams end up building expensive workarounds or dropping the feature entirely.
2. **Skip encryption:** The application stays fast, but when a breach happens, plaintext sensitive data is the first thing auditors ask about.

CipherStash gives you a third option.

DLAC extends access control down to individual encrypted values. Encryption happens inside your application before data reaches the database. Each value is stored as a single JSON payload containing the ciphertext alongside Searchable Encrypted Metadata (SEM). That is enough for Postgres to filter, sort, and join, but not enough to recover the original value. Queries are converted to SEM on the way in, Postgres matches against the stored SEM, and only the ciphertexts your application is authorized to decrypt come back. Every encrypted value carries a policy stating who can read it and under what condition. That policy is enforced at decryption, not at the query layer.

For teams under HIPAA, GDPR, or SOC 2, you keep Postgres, Supabase, and search, with a shorter compliance review and a smaller breach surface.

## How the integration works#

Add DLAC to your existing TypeScript application with CipherStash Stack. It works natively with Supabase.js, Drizzle, and Prisma Next. Encryption and decryption happen transparently in your application. Columns you mark as encrypted flow through the SDK and everything else behaves as it always has: `WHERE` clauses, fuzzy text matching, `ORDER BY`, and even JSON queries all continue to work over encrypted data.

Encryption keys are managed through ZeroKMS. Each encrypted value gets its own key, derived on demand, and keys can be split across regions to meet data residency requirements including frameworks like FedRAMP and IL4.

For cases where the SDK isn't a fit, such as analytics jobs, admin tooling, background workers in other languages, or anywhere you need direct database access outside your application, CipherStash Proxy provides a secure escape hatch. The proxy speaks the Postgres wire protocol and handles encryption and decryption transparently, so existing tools and SQL clients can work with encrypted data without code changes.

## Get started#

→ [Add CipherStash to your Supabase project](https://supabase.com/partners/integrations/cipherstash?utm_source=supabase_announcement_post&utm_medium=blog&utm_campaign=launch)
</Release>

<Release date="July 9, 2026" published="2026-07-09T00:00:00.000Z" url="https://www.prisma.io/changelog#learn-prisma-next-from-its-expanded-docs-and-use-native-post" org="prisma" source="prisma-changelog">
## Learn Prisma Next from its expanded docs and use native PostgreSQL enums

Prisma Next docs now cover Fundamentals, data modeling, migrations, middleware and extensions, contract authoring, and an API reference. The schema also reads native PostgreSQL enums.
</Release>

<Release date="July 9, 2026" published="2026-07-09T00:00:00.000Z" url="https://planetscale.com/changelog/query-insights-api-endpoints" org="planetscale" source="planetscale-changelog">
## Query Insights API endpoints

Query Insights data is now available through the public PlanetScale API. New endpoints let you programmatically access everything you see in the Insights dashboard:

- **Query statistics** — list branch queries with performance metrics, retrieve per-fingerprint statistics and summaries
- **Query errors** — list error summaries and the failed queries behind each error fingerprint
- **Anomalies** — list detected performance anomalies and their correlated queries
- **Query tags** — list tags on your queries, and group query statistics by tag
- **Traffic budgets** — list the traffic budgets affecting a query fingerprint (Postgres)

To use these with a service token, grant your token `read_database` permission.

**[Read more](https://planetscale.com/docs/api/reference/list_branch_queries)**
</Release>

<Release date="July 9, 2026" published="2026-07-09T00:00:00.000Z" url="https://planetscale.com/changelog/configure-read-only-region-replicas" org="planetscale" source="planetscale-changelog">
## Configure Vitess read-only region cluster sizes and replicas

You can now configure Vitess read-only regions per keyspace from the Clusters page in the dashboard. Choose a cluster size and a number of replicas for each region.

**[Read more](https://planetscale.com/docs/vitess/scaling/read-only-regions)**
</Release>

<Release version="v0.298.0" date="July 8, 2026" published="2026-07-08T22:53:00.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.298.0" org="planetscale" source="planetscale-cli">
## Changelog
* ded5a9053374fd624439afee8066fa9d81f1e782 Support Postgres branches in branch infra


</Release>

<Release version="v0.177.0" date="July 8, 2026" published="2026-07-08T22:20:21.000Z" url="https://github.com/planetscale/planetscale-go/releases/tag/v0.177.0" org="planetscale" source="planetscale-go-sdk">
## What's Changed
* Support Postgres branches in BranchInfrastructure by @nickvanw in https://github.com/planetscale/planetscale-go/pull/324


**Full Changelog**: https://github.com/planetscale/planetscale-go/compare/v0.176.0...v0.177.0
</Release>

<Release version="v0.297.0" date="July 8, 2026" published="2026-07-08T21:44:18.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.297.0" org="planetscale" source="planetscale-cli">
## Changelog
* e95be8e124e1a52f48732feb8911e69d2e39d6f1 Display replication under an attributes section
* a3cc98390382ef1f8acbc68cc67df097dccdb333 Support creating Postgres roles with replication


</Release>

<Release version="v0.296.0" date="July 8, 2026" published="2026-07-08T21:16:39.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.296.0" org="planetscale" source="planetscale-cli">
## Changelog
* 0300b6e844f1df228d75b11e231f3ca3f3fcd9fb Add structured JSON next_steps to workflow commands and a global JSON error envelope.
* 86989ca474a6b58989aad14875ad375ebd6ee7a8 Defer non-workflow errors to the global JSON classifier in workflow commands.
* 8220ab3d847f36dc7a1b5b1ec3e1bd3530ac37d6 Error on unknown root subcommands so JSON mode reports UNKNOWN_COMMAND.
* 008f9fee62f18e4247c1ef74dc8f3a317a672df3 Match both interactive-shell and interactive-terminal messages as TTY_REQUIRED.
* 4b14f756148631ad9be3329276e49368f2f21612 Merge branch 'main' into cli/workflow-json-next-steps
* 2cac4d562433522379cd97abd9f6036643f56359 Only classify transport-level failures as NETWORK_ERROR
* ab8a035fd10d3da24fe6a6cdff9bb827e1350966 Restore non-human format rejection for confirmation-gated workflow commands
* 838f2a7a53e95852c350cdf84e341de6b729f74e Revert "Error on unknown root subcommands so JSON mode reports UNKNOWN_COMMAND."
* 0651e90e9bc07b375864a0e6a8988ce5c2c0914d Revert workflow-specific JSON error handling to focus on the global envelope.
* b7ce77a05d7f7c01a308838eb7689a2698cd0ab5 Unify JSON error envelope on the issues schema, strip ANSI codes, document codes.
* 35f0f9aaaa19ef17f568d31bfe26bfda0c30e5c1 Write query patterns to stdout


</Release>

<Release version="v0.176.0" date="July 8, 2026" published="2026-07-08T20:38:18.000Z" url="https://github.com/planetscale/planetscale-go/releases/tag/v0.176.0" org="planetscale" source="planetscale-go-sdk">
## What's Changed
* Add `with_replication` to Postgres roles by @joshmgross in https://github.com/planetscale/planetscale-go/pull/323


**Full Changelog**: https://github.com/planetscale/planetscale-go/compare/v0.175.0...v0.176.0
</Release>

<Release version="v0.295.0" date="July 8, 2026" published="2026-07-08T19:05:58.000Z" url="https://github.com/planetscale/cli/releases/tag/v0.295.0" org="planetscale" source="planetscale-cli">
## Changelog
* d6eaf5e181cbc16a3dbbc60caf7625348aa3c06e Add DDL lint warnings for views, triggers, and non-simple indexes.
* 8aa1a3434f82c2c8e5609ef8cfb5fce00fe04471 Add pscale import d1 for Cloudflare D1 offline migration.
* ec6f38b4bcff4642ee698b3ea8896b37565a7285 Add support for proper uuid parsing
* 4ee747baaaecc84826d29723f4d53f0cbf3e6251 Aggregate Slack progress updates for table load and row-count verify.
* 9e93a49b7392f78b272d071ac5409427c75f4c6b Document import d1 in the embedded agent guide.
* 78f18823f3ef0758ff850afc6482dd6753581c6f Drop pgloader/sqlite3 from CI; D1 tests skip without them.
* 541a200a6b72be3bf23d603d54ab99a4fecd6f79 Fix D1 import failures to return prepared result context.
* 96cdadbcaeffeaea95649beb3d0d5a3cf2eecd8a Fix D1 import resume paths, pgloader validation, and JSON errors.
* c5ee72ef3735fa390e73878c9e10a8e1182bebb8 Fix D1 state persistence ordering and pgloader resume edge cases.
* 66a27a10f30619d58d2f5e26f98daccdf67eea19 Fix start resume using wrong Postgres dbname from state.
* 2b9a983ccf546913de0043339dc3aa2c5f0752ff Fix staticcheck De Morgan lint in simpleIndexColumnName.
* a54ef07c55599e8477b846192e7d193a9a308b08 Fix verify using wrong Postgres dbname from migration state.
* 6091962b97f67c1c24efd3b28904a9f987a033a3 Group human-readable lint issues by severity and code.
* a1760145ffb2d71005833de3b397c2dc52799722 Harden D1 import load path, verify, and resume correctness.
* 875ae19b29cb4b32ca8fca3c31a19cb6ed202243 Harden D1 import parsing, verify, and complete flow.
* f304ef0d6cc49390a8052b68be4f7df05ae9c96c Honor explicit --dbname when Import resolves migration db_name.
* 0f6863ee5918446c5eb9610585d9d8b2b0456a8d Limit D1 import role cleanup to d1-import-* names only.
* cf1d8c8b8cc0f772c342971b42e92b1db4f71239 Merge origin/main into import-d1.
* 2e227a0180b48a2192ac5b88c699062bfcd4e873 Merge remote-tracking branch 'origin/main' into import-d1
* 3f18afd88693aa0f0deda32d3f3d53c21040f391 More epoch time fixes
* 6a1121284c9ddc0f1598bcf29eae3567a5220721 Persist explicit --dbname during start --dry-run.
* ddc2c600b0d12ae8bf387f97f537e707baa87f08 Remove internal D1 pre-deploy checklist from the CLI repo.
* d0b2a4c35a6d24aa3f8bd3c81e21e25f430f7d1f Remove stale PRE_DEPLOY.md reference from ORM metadata comment.
* 024db0810552ae2efcb8457f37c23e051018aba4 Remove user-facing --no-notify flag from import d1 commands.
* 30dedc9b59a80a83af2ad9d1c97aea210a9c95c2 Run go fmt on ImportOptions after adding DBNameExplicit.
* be9edcb11af9b191c810a957b4896b5a0cdda0a9 Stop suggesting start --dry-run when lint errors block import.
* 4ee6289dc265cb65ec9a0117ff4ac75ac114a580 Untrack IMPORT-D1.md working notes (added by mistake).
* 0f6aaf25d982cd56c8248e450f1545dc83de7d4e lint fixes
* c12d3b6dfc4fda35c43b8a3d4f7ffe3f940c41fd throw an error if migration id is invalid during verification
* 3aec2a3e6bf07800a7d9f16d57169aefcb554a00 update gitignore


</Release>

<Pagination cursor="2026-07-08T19:05:58.000Z|2026-07-08T20:38:54.207Z|rel_2qcMLJBXZ-YAGlfHpXIdp" next="https://releases.sh/collections/serverless-postgres/releases?cursor=2026-07-08T19%3A05%3A58.000Z%7C2026-07-08T20%3A38%3A54.207Z%7Crel_2qcMLJBXZ-YAGlfHpXIdp&limit=20" />
