From ea67e9c491a3436841413e404183c0377243cd9c Mon Sep 17 00:00:00 2001 From: Inian Date: Fri, 27 Aug 2021 12:32:13 +0800 Subject: [PATCH] update security policy with out of scope vulns --- SECURITY.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 63dc5033611..7686a0b3621 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,6 +15,17 @@ At Supabase, we consider the security of our systems a top priority. But no matt If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems. +Out of scope vulnerabilities: + +- Clickjacking on pages with no sensitive actions. +- Unauthenticated/logout/login CSRF. +- Attacks requiring MITM or physical access to a user's device. +- Any activity that could lead to the disruption of our service (DoS). +- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS. +- Email spoofing +- Lack of Secure or HTTP only flag on non-sensitive cookies +- Deadlinks + Please do the following: - E-mail your findings to security@supabase.io.