update security policy with out of scope vulns

This commit is contained in:
Inian committed 2021-08-27 12:32:13 +08:00
1 parent 35c120c8e0
commit ea67e9c491
1 file changed
+11
+11
View File
@@ -15,6 +15,17 @@ At Supabase, we consider the security of our systems a top priority. But no matt
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.
Out of scope vulnerabilities:
- Clickjacking on pages with no sensitive actions.
- Unauthenticated/logout/login CSRF.
- Attacks requiring MITM or physical access to a user's device.
- Any activity that could lead to the disruption of our service (DoS).
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
- Email spoofing
- Lack of Secure or HTTP only flag on non-sensitive cookies
- Deadlinks
Please do the following:
- E-mail your findings to security@supabase.io.