/plushcap/analysis/supabase/supabase-hardening-supabase

Supabase Security Suite

What's this blog post about?

Over the past three months, the team has focused on enhancing security, performance, and stability in their platform. They have collaborated with Eva, a rising star in the world of security, who has been instrumental in discovering misconfigured projects and collaborating on fixes and features. The team's approach to security is based on a Shared Responsibility Model, providing developers full control while ensuring the most secure platform for development. They have launched several tools and guides, including Security Advisor, Lunchcat integration, API hardening, column-level security, user impersonation, RLS AI Assistant, network restrictions, and more. Future developments include improved Security Advisor, network restrictions 2.0, OpenAPI management, "Hard mode" development, CI/CD warnings, revamped API keys, and a private Vulnerability Disclosure Program with HackerOne.

Company
Supabase

Date published
July 11, 2024

Author(s)
Paul Copplestone

Word count
1465

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.