Skip to content

chore: remove SECURITY.md in favor of org-wide policy#2603

Open
spydon wants to merge 2 commits into
masterfrom
chore/remove-security-md-org-policy
Open

chore: remove SECURITY.md in favor of org-wide policy#2603
spydon wants to merge 2 commits into
masterfrom
chore/remove-security-md-org-policy

Conversation

@spydon

@spydon spydon commented Jun 29, 2026

Copy link
Copy Markdown

What

Removes this repo's SECURITY.md so it inherits the organization-wide security policy maintained centrally in supabase/.github.

References supabase/.github#20

Why

This repo's SECURITY.md is a stale fork of an older policy and now conflicts with the canonical org-wide one:

  • Reporting channel: it directs reporters to email security@supabase.io and request a scanner sandbox, whereas the canonical policy uses the HackerOne VDP (hackerone.com/supabase).
  • SLA: it promises a response "within 3 business days" versus the canonical "within 5 business days".

Inheriting the single org-wide default keeps the disclosure process consistent across every repository.

Note

Please do not merge until supabase/.github#20 is merged, otherwise this repo would briefly show no security policy.

@spydon spydon requested a review from a team as a code owner June 29, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant