mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
Adds a consumer-side guide for hardening npm installs of @supabase/* packages: lockfile hygiene, minimum-release-age quarantine across pnpm/yarn/npm/bun, private registries, provenance verification, lifecycle script controls, blocking exotic transitive refs, Edge Functions specifics, and an incident-response checklist. Lives at guides/security/ alongside platform-security and product-security; filesystem-driven sidebar picks it up automatically. Originally drafted in supabase/supabase-js#2382 and moved here per review. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added an npm security hardening guide (lockfile & CI practices, release-age quarantines, transitive/exotic dependency controls, provenance verification, lifecycle-script hardening, package-manager pinning, CI/lockfile hygiene, Deno/Edge guidance, incident-response checklist). * Added a navigation entry for the new guide. * Note: guide frontmatter contains unresolved merge-conflict markers. * **Chores** * Expanded spelling allowlist to include common tech terms (e.g., lockfile, sigstore, postinstall). <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46384?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>