From 5c4782c1552ed2d32cf1baad08660334a2833a4d Mon Sep 17 00:00:00 2001 From: Andrew Jackson Date: Mon, 14 Sep 2026 15:16:09 -0500 Subject: [PATCH] fix: isolate pg_net to pg_catalog extension This commit sets the only allowable place to install the net extension to pg_catalog. This is beneficial because in the absense of this the default place an extension will be installed when running `CREATE EXTENSION` will probably be public. This is often flagged as a security warning, on supabase for example but others as well. Looking at the postgres tree every procedural language is set up in this way (ie. relocatable=false, schema=pg_catalog). Besides procedural languages there is one extension that is nonrelocatable but does not specify schema though I believe that this may be an outlier. Outside of first party postgres extensions, pg_cron is also set up in this way (ie it create a cron scheam, creates all extension objects in there but ultimately the pg_cron extension itself is installed in pg_catalog and is non relocatable). --- pg_net.control.in | 1 + 1 file changed, 1 insertion(+) diff --git a/pg_net.control.in b/pg_net.control.in index cee9c0f1..85c46343 100644 --- a/pg_net.control.in +++ b/pg_net.control.in @@ -2,3 +2,4 @@ comment = 'Async HTTP' default_version = '@EXTVERSION@' relocatable = false module_pathname = '$libdir/pg_net' +schema = pg_catalog