Skip to content

Security: supabase/etl

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not report suspected security vulnerabilities in a public GitHub issue, discussion, pull request, log, or screenshot.

Report vulnerabilities privately through the Supabase Vulnerability Disclosure Program. Include the affected component and version or commit, the impact, reproduction steps, and a minimal proof of concept. Do not include customer data, production credentials, or more sensitive data than is necessary to demonstrate the issue.

Follow the scope, testing, safe-harbor, and disclosure requirements published by the program. Do not test against projects or data you do not own, disrupt services, or disclose the issue publicly before it has been investigated and coordinated.

Use GitHub issues for non-sensitive bugs and feature requests.

There aren't any published security advisories