What it is
SafeWeave reads Supabase's own security checks for the projects you choose: tables without Row Level Security, policies that are ignored because it's off, views that bypass it, functions with an unsafe search path, and more. Each project gets a grade and a list of findings with how to fix them.
SafeWeave only reads these checks. It never changes your project and never reads the data in your tables.
For an overview of what's checked and why it matters, see the Supabase RLS checker.
Who gets it
Cloud and Cloud Plus.
How to use it
- In the sidebar, click Integrations.
- On the Supabase card, click Connect Supabase.
- Supabase asks you to choose an organisation and approve SafeWeave. Approve it.
- Back on Integrations, tick Monitor next to each project you want checked. SafeWeave checks it straight away. After that it's checked once a day, and you can click Check now on the project's page at any time.
- Click a project's name to open its page.
What you'll see
- The project page shows the grade, the findings and, for each one, How to fix with a link to Supabase's guide.
- The Overview shows your monitored projects under Your Supabase projects. Their critical and high findings appear in Fix first. Projects are graded on their own and don't change your repository score.
- Every monitored project is checked once a day. If a check finds a new critical issue, you get an email.
- Your weekly security email lists each project's grade and what changed.
Limits
- You can monitor as many projects as your plan allows repositories.
- If Supabase doesn't answer, the check is marked as not finished and the previous results stay. It is never shown as clean. A project whose first check hasn't finished shows no grade yet.
If something goes wrong
- "Supabase access was revoked or expired.": click Reconnect on the Supabase card.
- A project is missing: SafeWeave sees the projects in the organisation you approved. Disconnect and connect again to choose another organisation.
- "Project not found in Supabase": the project was deleted or moved. It is no longer monitored.
- To stop: click Disconnect on the Supabase card. SafeWeave deletes its access straight away and keeps your history.