Do not open a public issue for a suspected vulnerability, exposed credential, or release supply-chain problem.
Report security issues through the Supabase vulnerability disclosure program. Include the affected service and version, artifact or image digest, target platform, reproduction steps, and an impact assessment when available.
The authoritative disclosure and testing policy is published at supabase.com/.well-known/security.txt. In particular, do not test against customer projects or use disruptive automated scanning.