If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Use GitHub's private vulnerability reporting
- Include: description, reproduction steps, impact assessment
We will acknowledge within 48 hours and provide a fix timeline within 7 days.
| Version | Supported |
|---|---|
| Latest | Yes |
| < Latest | No — please upgrade |
- Never expose Supabase service role key publicly
- Rotate VAPID keys periodically
- Keep your
.envfiles out of version control - Use HTTPS in production (Caddy handles this automatically)
- Set
ALLOWED_ORIGINSon Edge Functions to your domain only