The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more. https://grafana.com
  • TypeScript 50.3%
  • Go 47.4%
  • CUE 0.6%
  • Rich Text Format 0.4%
  • JavaScript 0.3%
  • Other 0.8%
Find a file
Peter Štibraný eb4b688df8
Search: refuse federated trash queries (#129868)
Trash authorizes each hit against a single index's group and resource. A
federated search joins in hits from another index, which would then be checked
against the wrong one, so trash and federation cannot be combined.

Refused in two places. searchServer.Search rejects the request before it
resolves the federated indexes, because resolving one can build an index. The
bleve index repeats the check for callers that reach it directly, next to the
rule that keeps trash-only fields out of a live search, so a read path cannot
apply one rule without the other.

The only caller that sets both flags is the legacy /api/search?deleted=true
path, which federates dashboards and folders whenever no type is given. That
path returns nothing today: deleted objects only enter the index when
index_deleted_documents is set, and it defaults to off. Nothing in the frontend
calls it either, so this turns an empty response into an error rather than
changing a working one.
2026-08-01 18:52:04 +02:00
.changelog-archive
.citools
.claude/skills docs(skills): add panel-testing-strategy skill (#129154) 2026-07-31 21:20:56 +00:00
.github docs(skills): add panel-testing-strategy skill (#129154) 2026-07-31 21:20:56 +00:00
.vim
.vscode
.yarn
apps Provisioning: (3/8) Rework connection token validation (#129740) 2026-07-31 11:34:02 -05:00
conf Provisioning: Document allowed_git_urls setting (#129670) 2026-07-30 11:54:40 +00:00
contribute MySQL: Remove from core plugins (#129439) 2026-07-30 08:37:03 -05:00
cue.mod
devenv Build: Separate Swagger from Grafana assets (#123798) 2026-07-31 15:20:33 +01:00
docs Docs: document CloudWatch Logs data source queries (#129343) 2026-07-31 11:43:00 -07:00
e2e-playwright test: Migrate E2E to page objects (PR #21) (#129847) 2026-07-31 15:39:37 +02:00
emails
grafana-mixin
hack
kinds Dashboards: Add optional valueExpr field to Threshold struct (#128501) 2026-07-28 15:16:44 +03:00
local
packages docs(skills): add panel-testing-strategy skill (#129154) 2026-07-31 21:20:56 +00:00
packaging
pkg Search: refuse federated trash queries (#129868) 2026-08-01 18:52:04 +02:00
public I18n: Download translations from Crowdin (#129898) 2026-08-01 00:57:42 +00:00
scripts Build: Separate Swagger from Grafana assets (#123798) 2026-07-31 15:20:33 +01:00
tools
.air.toml
.browserslistrc
.dockerignore
.editorconfig
.gitattributes
.gitignore docs(skills): add panel-testing-strategy skill (#129154) 2026-07-31 21:20:56 +00:00
.golangci.yml MySQL: Remove from core plugins (#129439) 2026-07-30 08:37:03 -05:00
.ignore
.levignore.js
.madgerc
.nvmrc
.nxignore
.policy.yml CI: Trigger storybook preview on grafana-data theme changes (#129423) 2026-07-29 06:37:32 +01:00
.policy.yml.tmpl
.prettierignore Prettier: anchor build and data ignore patterns to repo root (#129781) 2026-07-31 09:34:41 +01:00
.prettierrc.js
.vale.ini
.yarnrc.yml Chore: Use lokiGrammar from @grafana/lezer-logql package (#128913) 2026-07-21 19:35:29 +02:00
AGENTS.md MySQL: Remove from core plugins (#129439) 2026-07-30 08:37:03 -05:00
CHANGELOG.md
CLAUDE.md
CODE_OF_CONDUCT.md
CONTRIBUTING.md
crowdin.yml
Dockerfile
embed.go
eslint-suppressions.json Chore: fix eslint suppressions — no-locale-compare in grafana-testdata QueryEditor (#129813) 2026-07-31 09:26:28 +02:00
eslint.config.js MySQL: Remove from core plugins (#129439) 2026-07-30 08:37:03 -05:00
go.mod Alerting: bump historian module to latest (#129564) 2026-07-29 14:12:11 +00:00
go.sum Alerting: bump historian module to latest (#129564) 2026-07-29 14:12:11 +00:00
go.work
go.work.sum Alerting: bump historian module to latest (#129564) 2026-07-29 14:12:11 +00:00
GOVERNANCE.md
HALL_OF_FAME.md
i18next.config.ts
jest.config.codeowner.js
jest.config.js Chore: Bump @grafana/aws-sdk to 0.12.0 for per-DS external ID UI (#129748) 2026-07-31 13:24:20 -04:00
knip.config.ts MySQL: Remove from core plugins (#129439) 2026-07-30 08:37:03 -05:00
latest.json
lefthook.rc
lefthook.yml
lerna.json
LICENSE
LICENSING.md
MAINTAINERS.md
Makefile Extract core Wire graph into bootstrap/wire package (GE standalone step 01) (#128152) 2026-07-23 15:00:26 +00:00
mise.toml
NOTICE.md
nx.json
package.json Chore: Bump @grafana/aws-sdk to 0.12.0 for per-DS external ID UI (#129748) 2026-07-31 13:24:20 -04:00
playwright.config.ts Loki: Remove from core plugins (#129092) 2026-07-27 16:54:25 +02:00
playwright.storybook.config.ts
project.json Build: Separate Swagger from Grafana assets (#123798) 2026-07-31 15:20:33 +01:00
README.md docs: remove deprecated Go Report Card badge (#129468) 2026-07-29 22:26:57 +09:00
relyance.yaml
ROADMAP.md
stylelint.config.js
SUPPORT.md
tsconfig.json
tsconfig.smoke.json Chore: clean up node options (#128861) 2026-07-31 10:59:18 +02:00
WORKFLOW.md
yarn.config.cjs
yarn.lock Chore: Bump @grafana/aws-sdk to 0.12.0 for per-DS external ID UI (#129748) 2026-07-31 13:24:20 -04:00

Grafana Logo (Light) Grafana Logo (Dark)

The open-source platform for monitoring and observability

License

Grafana allows you to query, visualize, alert on and understand your metrics no matter where they are stored. Create, explore, and share dashboards with your team and foster a data-driven culture:

  • Visualizations: Fast and flexible client side graphs with a multitude of options. Panel plugins offer many different ways to visualize metrics and logs.
  • Dynamic Dashboards: Create dynamic & reusable dashboards with template variables that appear as dropdowns at the top of the dashboard.
  • Explore Metrics: Explore your data through ad-hoc queries and dynamic drilldown. Split view and compare different time ranges, queries and data sources side by side.
  • Explore Logs: Experience the magic of switching from metrics to logs with preserved label filters. Quickly search through all your logs or streaming them live.
  • Alerting: Visually define alert rules for your most important metrics. Grafana will continuously evaluate and send notifications to systems like Slack, PagerDuty, VictorOps, OpsGenie.
  • Mixed Data Sources: Mix different data sources in the same graph! You can specify a data source on a per-query basis. This works for even custom datasources.

Get started

Unsure if Grafana is for you? Watch Grafana in action on play.grafana.org!

Documentation

The Grafana documentation is available at grafana.com/docs.

Contributing

If you're interested in contributing to the Grafana project:

Share your contributor experience in our feedback survey to help us improve.

Get involved

This project is tested with BrowserStack.

License

Grafana is distributed under AGPL-3.0-only. For Apache-2.0 exceptions, see LICENSING.md.