Neon Security & compliance

Unprotected role on the primary/protected branch

Part of the Cost & ops health check · fix arrives as a guide

What it is

A database role on the primary or a protected branch is not marked as protected.

Why it matters

The rule reads this against the IP allow-list: a role that the allow-list does not cover is reachable from outside the ranges you meant to permit. On the primary branch that role is your production credentials.

How to fix it

Mark the roles used against protected branches as protected in the Neon console, so they fall inside the allow-list's scope rather than outside it.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.