mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
update security policy with out of scope vulns
This commit is contained in:
1 parent
35c120c8e0
commit
ea67e9c491
1 file changed
+11
+11
@@ -15,6 +15,17 @@ At Supabase, we consider the security of our systems a top priority. But no matt
|
||||
|
||||
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.
|
||||
|
||||
Out of scope vulnerabilities:
|
||||
|
||||
- Clickjacking on pages with no sensitive actions.
|
||||
- Unauthenticated/logout/login CSRF.
|
||||
- Attacks requiring MITM or physical access to a user's device.
|
||||
- Any activity that could lead to the disruption of our service (DoS).
|
||||
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
|
||||
- Email spoofing
|
||||
- Lack of Secure or HTTP only flag on non-sensitive cookies
|
||||
- Deadlinks
|
||||
|
||||
Please do the following:
|
||||
|
||||
- E-mail your findings to security@supabase.io.
|
||||
|
||||
Reference in new issue
Block a user