Built an open-source CI check that fails when live Supabase privileges drift from what your migrations define. For example, if a dashboard change accidentally gives anon access to a table. In my tests, supabase db diff didn’t catch that case.
Scope: Postgres grants only, including table, schema, and default privileges for anon / authenticated roles. It does not cover RLS, column-level grants, or function EXECUTE.
I’d love a few people to try:
npx supabase-drift-guard check .
on a real project and tell me whether the output looks right, noisy, or broken.
Sirine Sarray introduces an open-source CI tool, supabase-drift-guard, designed to detect discrepancies between live Supabase privileges and those defined in migrations. The tool focuses on Postgres grants for anon and authenticated roles, excluding RLS and other specific privileges. Sirine invites users to test the tool and provide feedback on its effectiveness.