supabase-rls-linter
v1.2.0
Published
AST-based high-performance security linter, rule engine, and webhook auditor for Supabase, Stripe, and Clerk Auth integrations.
Maintainers
Readme
🛡️ Supabase RLS Guardian (linter)
Supabase RLS Guardian is a zero-dependency, high-performance AST static analyzer and security linter built to eradicate Row Level Security (RLS) data leaks, unindexed foreign key performance traps, and recursive policy loops in Supabase and PostgreSQL databases.
⚡ Quick Start
Scan your Supabase database migrations instantly in terminal or CI/CD:
npx supabase-rls-linter ./supabase/migrationsOptions & Flags
# Generate interactive Glassmorphism HTML Audit Dashboard
npx supabase-rls-guardian ./supabase/migrations --html audit-report.html
# Fail CI pipeline if CRITICAL security issues are detected
npx supabase-rls-guardian ./supabase/migrations --fail-on-critical
# Emit GitHub Actions workflow annotations for inline PR code reviews
npx supabase-rls-guardian ./supabase/migrations --github-actions🔍 Core Security & Performance Rules
| Rule ID | Name | Category | Severity | Description |
| :--- | :--- | :--- | :--- | :--- |
| RLS001 | Missing Row Level Security | Security | CRITICAL | Flags tables created without ENABLE ROW LEVEL SECURITY. |
| RLS002 | Overly Permissive Policy | Security | CRITICAL | Detects USING (true) or WITH CHECK (true) on public/anon roles. |
| RLS003 | Unnecessary Service Role Check | Best Practice | WARNING | Identifies redundant TO service_role client policy declarations. |
| RLS004 | Unindexed FK Security Join | Performance | WARNING | Catches subquery checks against foreign columns missing database indexes. |
| RLS005 | Recursive Policy Infinite Loop | Security | CRITICAL | Prevents infinite loop RLS self-referencing subquery crashes. |
| RLS006 | Insecure SECURITY DEFINER RPC | Security | HIGH | Flags RPC functions missing explicit SET search_path = ''. |
🖥️ Terminal Audit Preview
===============================================================
SUPABASE RLS GUARDIAN - SECURITY AUDIT
===============================================================
Target Schema: ./supabase/migrations/20260729_schema.sql
Security Health Score: [17%] (Grade F - CRITICAL RISK)
Tables Analyzed: 4 (3 Protected with RLS)
Found 5 issues:
[1] 🚨 [CRITICAL] RLS001: Missing Row Level Security
Table: profiles | Line: 5
Issue: Table "profiles" is missing RLS. Data is publicly accessible unless restricted.
💡 Fix Suggestion: ALTER TABLE profiles ENABLE ROW LEVEL SECURITY;
[2] 🚨 [CRITICAL] RLS005: Recursive Policy Infinite Loop
Table: team_members | Line: 42
Issue: Policy "Recursive Member View" queries table "team_members" inside its condition.
💡 Fix Suggestion: Refactor policy to use security definer helper functions.🎨 Glassmorphism HTML Security Dashboard
Generate an interactive visual dashboard report using --html report.html:

🤖 GitHub Actions Integration
Add inline PR annotations and automated blocking checks to your repository:
name: RLS Security Audit
on: [push, pull_request]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: Audit Supabase Schema
run: npx supabase-rls-guardian ./supabase/migrations --github-actions --fail-on-critical