eslint-plugin-supabase-security
Supabase security — service_role exposure, RPC names, auth errors, bucket visibility
AI-Optimized Security
Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.
Install
npm install -D eslint-plugin-supabase-securityLive from GitHub
This content is fetched directly from README.md on GitHub and cached for 1 hour.
⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.
Description
Security rules for @supabase/supabase-js (service_role key reaching the client, computed RPC names, discarded auth errors, public storage buckets).
Scope: this plugin lints the client's API shapes — which key reaches the browser, what .rpc() is handed, whether an auth result's error is read, how a bucket is created. Every rule gates on a @supabase/* package actually being imported, because .rpc(), .auth and createBucket() are ordinary member names that any codebase may own.
What it does not do: infer whether a table has Row Level Security enabled, or whether a policy covers a given query. That lives in the database, not in the source. A rule that guessed at it would be a rule about naming conventions, and this repo does not ship those.
The rule that justifies the package is no-service-role-key-in-client. service_role bypasses RLS completely — it is a database superuser in a string — and the line that leaks it is indistinguishable from every other createClient call, which is exactly why review does not catch it.
- Why — a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
- How — evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
- What — every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.
That trade costs recall, and we measure it: methodology · results · a false positive is a bug.
Getting Started
- To check out the guide, visit eslint.interlace.tools. 📚
npm install eslint-plugin-supabase-security --save-dev⚙️ Configuration Presets
| Preset | Description |
|---|---|
minimal | no-service-role-key-in-client only — the one rule nobody should ship without. |
recommended | The three rules whose abstentions are structural: service-role, dynamic RPC, auth error. |
strict | Every rule, including no-public-storage-bucket — a public bucket is sometimes intended, so it waits here. |
Usage
// eslint.config.js
import supabaseSecurity from 'eslint-plugin-supabase-security';
export default [supabaseSecurity.configs.recommended];Or wire the rules yourself:
import supabaseSecurity from 'eslint-plugin-supabase-security';
export default [
{
plugins: { 'supabase-security': supabaseSecurity },
rules: {
'supabase-security/no-service-role-key-in-client': 'error',
},
},
];oxlint
Every rule in this plugin runs on oxlint as well as ESLint:
{ "jsPlugins": ["eslint-plugin-supabase-security/oxlint"] }📦 Compatibility
See the ESLint Version Support Policy for the full matrix.
Rules
Legend
| Icon | Description |
|---|---|
| 💼 | Recommended: Included in the recommended preset. |
| ⚠️ | Warns: Set to warn in recommended preset. |
| 🔧 | Auto-fixable: Automatically fixable by the --fix CLI option. |
| 💡 | Suggestions: Providing code suggestions in IDE. |
| 🚫 | Deprecated: This rule is deprecated. |
| 🟢 | Type-unaware: AST-only, runs in oxlint JS-plugin tier. |
| 🟡 | Type-aware (refining): pure-AST primary path; types refine precision. |
| 🟠 | Type-aware (graceful): requires TS program; silent without it. |
| Rule | CWE | OWASP | CVSS | Description | 🧠 | 💼 | ⚠️ | 🔧 | 💡 | 🚫 |
|---|---|---|---|---|---|---|---|---|---|---|
| no-dynamic-rpc-name | CWE-913 | A03:2021 | Call .rpc() with a literal function name | 🟢 | ||||||
| no-public-storage-bucket | CWE-732 | A01:2021 | Do not create a Supabase storage bucket as public | 🟢 | ||||||
| no-service-role-key-in-client | CWE-798 | A02:2021 | Keep the Supabase service_role key out of client code | 🟢 | ||||||
| require-auth-error-check | CWE-287 | A07:2021 | Read error from a Supabase auth result | 🟢 |
⭐ Support & follow
If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.
🔗 Related ESLint Plugins
Part of the Interlace ESLint ecosystem — AI-native rules with LLM-optimized error messages:
Security
Code quality
| Plugin | Downloads | Description |
|---|---|---|
eslint-plugin-conventions | Team-specific habits and styles. | |
eslint-plugin-import-next | Fast cycle + import-graph analysis. | |
eslint-plugin-maintainability | Cognitive load and clean-code patterns. | |
eslint-plugin-modernization | ESNext migration + syntax evolution. | |
eslint-plugin-modularity | Structural integrity and DDD patterns. | |
eslint-plugin-operability | Production readiness and resource health. | |
eslint-plugin-react-a11y | React accessibility / WCAG. | |
eslint-plugin-react-features | React best practices and optimization. | |
eslint-plugin-reliability | Runtime stability and error safety. |
📄 License
MIT © Ofri Peretz
Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.