Skip to content

db push applies migrations when the confirmation answer is not yes or no #6869

Description

@aklarby

Affected area

Migrations

Supabase CLI version

2.107.0 (Homebrew). The CLI also reported that 2.118.0 is available.

Operating system

macOS (darwin 25.6.0, arm64)

Installation method

brew (/opt/homebrew/bin/supabase, package supabase@2.107.0)

Command

supabase db push

At the confirmation prompt the answer entered was u, then Enter. That is not y or n.

Actual output

Do you want to push these migrations to the remote database?
 • <pending-migration>.sql

 [Y/n] u
Applying migration <pending-migration>.sql...
Finished supabase db push.

A second supabase db push then reported Remote database is up to date. The migration had been applied.

Expected behavior

[Y/n] means Enter, y, and yes confirm, and n and no decline. Any other non-empty answer should be rejected.

On an interactive terminal the prompt should say the answer was not recognized and ask again. It should not apply migrations. When stdin is not a terminal, a non-empty unrecognized answer should fail the command instead of taking the default. An empty line can still take the default, which is what Enter means.

Steps to reproduce

  1. Use Supabase CLI 2.107.0, linked to a remote project that has at least one pending migration. --dry-run shows the same prompt path without writing.
  2. Run supabase db push.
  3. At [Y/n], type u and press Enter.
  4. The pending migration is applied.

The same parser is what makes printf 'u\n' dangerous anywhere this prompt reads a line and the default is yes.

Additional context

On 2.107.0, db push confirms through PromptYesNo in apps/cli-go/internal/utils/console.go, called with the default set to true from apps/cli-go/internal/db/push/push.go. parseYesNo accepts only y/yes/n/no. Any other non-empty string, including u, returns nil, and PromptYesNo then returns the default:

input, err := c.PromptText(ctx, labelWithChoice)
if len(input) > 0 {
    if answer := parseYesNo(input); answer != nil {
        return *answer, nil
    }
}
return def, err

There is no re-prompt and no message that the input was ignored. For db push, def is true, so a typo applies remote migrations.

On current develop (and the 2.118.0 tree), apps/cli-go/internal/db/push/push.go is gone and interactive db push goes through promptYesNo in apps/cli/src/command-internal/prompt-yes-no.ts. A real TTY uses clack confirm, where y and n submit immediately and Enter submits the initial value. That interactive UI does not show the [Y/n] u line from 2.107.0. The shared fallback is still there for a non-TTY read: a non-empty line that parseYesNo does not understand falls through to defaultValue, and db push passes true. The Go PromptYesNo helper is also still used by other confirmations (db reset, migration repair, migration down, seed buckets) with the same fallback.

I am not opening a pull request yet. CONTRIBUTING.md says an external PR has to wait until this issue is open and carries open-for-contribution, and .github/scripts/contribution-gate.ts closes PRs that skip that. Happy to send the fix once that label is on.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions