Neon
Security & compliance
Unprotected role on the primary/protected branch
Part of the Cost & ops health check · fix arrives as a guide
What it is
A database role on the primary or a protected branch is not marked as protected.
Why it matters
The rule reads this against the IP allow-list: a role that the allow-list does not cover is reachable from outside the ranges you meant to permit. On the primary branch that role is your production credentials.
How to fix it
Mark the roles used against protected branches as protected in the Neon console, so they fall inside the allow-list's scope rather than outside it.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.