Security checklist

GitHub security checklist before launching a web app

A practical repository security checklist for secrets, access control, database rules, dependencies, payments and production configuration.

Quick Scan First robot reviewing connected repository files before launch
A consistent checklist turns scattered release risks into a reviewable process.

1. Search for secrets and committed environment files

Check the full repository and history for .env files, tokens, API keys, database passwords and private keys. If a real secret was committed, revoke it before cleaning the repository.

2. Test authentication and ownership

Authentication answers who the user is; authorisation answers what that user may do. Verify both on the server for every protected read and write, including direct API requests that bypass the interface.

3. Review database security rules

Firebase and Supabase defaults can become dangerous when broad development rules reach production. Confirm that rules are deployed, Row Level Security is enabled where required, and policies cover read, create, update and delete operations.

4. Verify payment boundaries

Calculate prices on the server, verify webhook signatures, make processing idempotent, and never trust product IDs, amounts or account ownership supplied only by the browser.

5. Check dependencies and production setup

Review known vulnerabilities, lockfiles, production URLs, CORS, security headers, error handling and monitoring. Test the actual built application, not only the development server.

Frequently asked questions

Is a checklist enough to secure an application?

No. It creates consistency, but higher-risk products also need threat modelling, testing, monitoring and expert review.

Should checks run once or continuously?

Run them before launch and again after changes to authentication, payments, data access, dependencies or deployment configuration.