IP allow-list not scoped to protected branches
Part of the Cost & ops health check · fix arrives as a guide
What it is
The project has an IP allow-list, but it is not scoped to protected branches — so the same rules apply to every branch endpoint.
Why it matters
Neon lets you narrow the allow-list to protected branches only. Which way that toggle should sit depends on your setup, and it is worth deciding rather than inheriting: unscoped applies one policy to production and preview branches alike, while scoping it lifts the restriction from every non-protected branch.
How to fix it
Check the toggle against how your team actually connects. If developers reach preview branches from changing addresses, scoping the allow-list to protected branches keeps production guarded while unblocking them — and should be paired with short-lived branches and separate credentials. If every branch holds data worth restricting, leave it unscoped.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.