[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmau4q2thrq42":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6abbca2dca21c797c7e9d948","github---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8","GitHub - guptaaman678\u002Fsupabase-grants-lint: Lint Supabase migrations for tables the Data API cannot reach once auto-grants end on 2026-10-30.","Find the Supabase migrations that break on a fresh environment: tables the Data API cannot reach (PostgREST 42501 permission denied for table) once new tables stop getting automatic grants.","news",[10,13,18,23,28,33,38,43,48,53],{"headline":11,"body":7,"imageUrl":12,"sourceImageUrl":12},"GitHub - guptaaman678\u002Fsupabase-grants-lint: Lint Supabase migrations for tables…","https:\u002F\u002Fopengraph.githubassets.com\u002Ffe553f875261e054a1bb115324ade98f8b24f5158e30d68fe5b8c86d9ba7f3b0\u002Fguptaaman678\u002Fsupabase-grants-lint",{"headline":14,"body":15,"imageUrl":16,"images":17},"It replays your SQL migrations, works out who","It replays your SQL migrations, works out who can reach every table, and prints the grant that fixes each finding. It reads files only: no database connection, no telemetry. In a project with a supabase\u002Fmigrations folder (Node 22 or later): Run it from your project root, the folder that contains supabase\u002F, or pass --dir. check lints the migrations and exits 1 on an error finding.","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"doctor is a readiness report for 2026-10-30: whether","doctor is a readiness report for 2026-10-30: whether the project is opted in, whether replaying the history turns automatic grants back on, and which existing tables a fresh database would not expose. To run it on every pull request:","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"This writes grants-lint.config.json and .github\u002Fworkflows\u002Fgrants-lint.yml.","This writes grants-lint.config.json and .github\u002Fworkflows\u002Fgrants-lint.yml. --since next enforces every migration you add from now on and leaves the existing ones alone. Commit both files and open a pull request: the check runs on it. What breaks on 2026-10-30","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"Supabase has announced that from 2026-10-30 new tables","Supabase has announced that from 2026-10-30 new tables, views and sequences in public stop getting automatic grants for anon, authenticated and service_role on every existing project. Preview branches already work this way, and so can new projects and local stacks with auto_expose_new_tables = false. A migration that creates a table and forgets to grant applies cleanly, row level security looks right, and the first request fails. Five traps are easy to miss:","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"Replaying history turns the grants back on. A","Replaying history turns the grants back on. A baseline made with supabase db pull can contain alter default privileges ... grant all, so local resets and preview branches give new tables grants production no longer has (GL007).","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"The revoke is narrow. Per the SQL Supabase","The revoke is narrow. Per the SQL Supabase published, it removes select, insert, update and delete (and sequence usage, select), and leaves truncate, references and trigger (plus maintain on Postgres 17+) on every new table (GL008).","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"service_role bypasses row level security, not grants. Edge","service_role bypasses row level security, not grants. Edge functions and admin tools using the service role key get 42501 too (GL001).","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"Policies without grants are dead. create policy","Policies without grants are dead. create policy ... to authenticated on a table authenticated holds no grant on never applies (GL002, GL003).","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"serial columns need their sequence. A client that","serial columns need their sequence. A client that inserts into a table with a serial column needs usage on its sequence; identity columns and uuid keys do not (GL004).","\u002Fapi\u002Fmedia\u002Fposts\u002Fgithub---guptaaman678supabase-grants-lint-lint-supabase-migr-c57f00a8\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Show HN","https:\u002F\u002Fgithub.com\u002Fguptaaman678\u002Fsupabase-grants-lint","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},3,0,"2026-09-29T14:24:45.371Z","local"]