Skip to main content
interlace
SecurityPlugin: supabase-security

eslint-plugin-supabase-security

Supabase security — service_role exposure, RPC names, auth errors, bucket visibility

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.

Install

npm install -D eslint-plugin-supabase-security

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

Live README from GitHubfrom eslint-plugin-supabase-security/README.md, cached for 1 hour.Edit on GitHub

⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.

Description

Security rules for @supabase/supabase-js (service_role key reaching the client, computed RPC names, discarded auth errors, public storage buckets).

Scope: this plugin lints the client's API shapes — which key reaches the browser, what .rpc() is handed, whether an auth result's error is read, how a bucket is created. Every rule gates on a @supabase/* package actually being imported, because .rpc(), .auth and createBucket() are ordinary member names that any codebase may own.

What it does not do: infer whether a table has Row Level Security enabled, or whether a policy covers a given query. That lives in the database, not in the source. A rule that guessed at it would be a rule about naming conventions, and this repo does not ship those.

The rule that justifies the package is no-service-role-key-in-client. service_role bypasses RLS completely — it is a database superuser in a string — and the line that leaks it is indistinguishable from every other createClient call, which is exactly why review does not catch it.

  • Why — a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
  • How — evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
  • What — every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.

That trade costs recall, and we measure it: methodology · results · a false positive is a bug.

Getting Started

npm install eslint-plugin-supabase-security --save-dev

⚙️ Configuration Presets

PresetDescription
minimalno-service-role-key-in-client only — the one rule nobody should ship without.
recommendedThe three rules whose abstentions are structural: service-role, dynamic RPC, auth error.
strictEvery rule, including no-public-storage-bucket — a public bucket is sometimes intended, so it waits here.

Usage

// eslint.config.js
import supabaseSecurity from 'eslint-plugin-supabase-security';

export default [supabaseSecurity.configs.recommended];

Or wire the rules yourself:

import supabaseSecurity from 'eslint-plugin-supabase-security';

export default [
  {
    plugins: { 'supabase-security': supabaseSecurity },
    rules: {
      'supabase-security/no-service-role-key-in-client': 'error',
    },
  },
];

oxlint

Every rule in this plugin runs on oxlint as well as ESLint:

{ "jsPlugins": ["eslint-plugin-supabase-security/oxlint"] }

📦 Compatibility

PackageVersion
@supabase/supabase-jsnpm
ESLintnpm
Node.jsnode

See the ESLint Version Support Policy for the full matrix.

Rules

Legend

IconDescription
💼Recommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
🔧Auto-fixable: Automatically fixable by the --fix CLI option.
💡Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟢Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟡Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescription🧠💼⚠️🔧💡🚫
no-dynamic-rpc-nameCWE-913A03:2021Call .rpc() with a literal function name🟢
no-public-storage-bucketCWE-732A01:2021Do not create a Supabase storage bucket as public🟢
no-service-role-key-in-clientCWE-798A02:2021Keep the Supabase service_role key out of client code🟢
require-auth-error-checkCWE-287A07:2021Read error from a Supabase auth result🟢

⭐ Support & follow

If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

Part of the Interlace ESLint ecosystem — AI-native rules with LLM-optimized error messages:

Security

PluginDownloadsDescription
eslint-plugin-anthropic-securitydownloadsAnthropic SDK security.
eslint-plugin-browser-securitydownloadsXSS, DOM security.
eslint-plugin-drizzle-securitydownloadsDrizzle security.
eslint-plugin-express-securitydownloadsExpress middleware hardening.
eslint-plugin-gemini-securitydownloadsGoogle Gemini SDK security.
eslint-plugin-jwt-securitydownloadsToken security.
eslint-plugin-knex-securitydownloadsKnex security.
eslint-plugin-lambda-securitydownloadsAWS Lambda hardening.
eslint-plugin-mcp-sdk-securitydownloadsMCP SDK security.
eslint-plugin-mongodb-securitydownloadsMongoDB injection.
eslint-plugin-mysql-securitydownloadsMySQL security.
eslint-plugin-nestjs-securitydownloadsNestJS framework hardening.
eslint-plugin-node-securitydownloadsServer-side patterns.
eslint-plugin-openai-securitydownloadsOpenAI SDK security.
eslint-plugin-postgresql-securitydownloadsPostgreSQL security.
eslint-plugin-prisma-securitydownloadsPrisma security.
eslint-plugin-secure-codingdownloadsInjection prevention.
eslint-plugin-sequelize-securitydownloadsSequelize ORM security.
eslint-plugin-sqlite-securitydownloadsSQLite security.
eslint-plugin-typeorm-securitydownloadsTypeORM security.
eslint-plugin-vercel-ai-securitydownloadsAI SDK security.

Code quality

PluginDownloadsDescription
eslint-plugin-conventionsdownloadsTeam-specific habits and styles.
eslint-plugin-import-nextdownloadsFast cycle + import-graph analysis.
eslint-plugin-maintainabilitydownloadsCognitive load and clean-code patterns.
eslint-plugin-modernizationdownloadsESNext migration + syntax evolution.
eslint-plugin-modularitydownloadsStructural integrity and DDD patterns.
eslint-plugin-operabilitydownloadsProduction readiness and resource health.
eslint-plugin-react-a11ydownloadsReact accessibility / WCAG.
eslint-plugin-react-featuresdownloadsReact best practices and optimization.
eslint-plugin-reliabilitydownloadsRuntime stability and error safety.

📄 License

MIT © Ofri Peretz

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.