Supabase Security Suite
Over the past three months, the team has focused on enhancing security, performance, and stability in their platform. They have collaborated with Eva, a rising star in the world of security, who has been instrumental in discovering misconfigured projects and collaborating on fixes and features. The team's approach to security is based on a Shared Responsibility Model, providing developers full control while ensuring the most secure platform for development. They have launched several tools and guides, including Security Advisor, Lunchcat integration, API hardening, column-level security, user impersonation, RLS AI Assistant, network restrictions, and more. Future developments include improved Security Advisor, network restrictions 2.0, OpenAPI management, "Hard mode" development, CI/CD warnings, revamped API keys, and a private Vulnerability Disclosure Program with HackerOne.
Company
Supabase
Date published
July 11, 2024
Author(s)
Paul Copplestone
Word count
1465
Language
English
Hacker News points
None found.