Supabase

Connect a Supabase organization read-only and turn its security advisor results and public storage buckets into findings.

Edit on GitHub

LaunchSafe can check a Supabase project's security settings and report problems as ordinary findings.

What it does

  • You approve the connection. Only someone who can approve LaunchSafe on the Supabase organization can connect it, through Supabase's own consent screen. LaunchSafe never probes a project from outside.
  • Read only. It reads your organizations and projects, Supabase's security advisor results and the list of storage buckets. It never writes to a project and never reads your table data. Evidence names the schema and the object, never a row.
  • Disconnecting revokes the grant at Supabase and deletes the stored tokens. Your scans and findings stay.

Use it

Connect

Under Integrations, connect Supabase. Owners and admins can connect, with a recent sign-in.

Link a project

Link each Supabase project to a LaunchSafe project.

Run a check

Run the check on a linked project. It is free and uses no AI. Members can run it too. One check of a project runs at a time.

What you get

Findings with the source Supabase settings. They appear in Findings, on the project and in reports, and the report says a settings check read the project. A check that could only read part of a project, for example when it is paused, says which part it did not read.

A finding that a later check no longer sees is closed as fixed, but only when the part that reports it was read.

Fixing

Supabase findings have no fix pull request and no engine retest. Fix the setting in Supabase, or copy the fix prompt for a migration. Running the check again is the retest.

Not available yet

  • A daily re-check: checks run when you run them.
  • One-click fixes in Supabase.
  • Plan limits on connected Supabase projects are not set.

If Supabase is not set up on the server you use, its card says so.

On this page