envtrap.json Configuration Reference
Configure envtrap by placing an envtrap.json file in your project root (adjacent to package.json).
All configuration options are optional. When a field is omitted, envtrap applies safe, production-grade defaults automatically.
Complete Schema & Defaults
envtrap.json
Schema Properties
channels
- Type:
object - Default: See schema above
"block": Prevent the leak. Network sockets are severed, DNS and child process calls throw errors, and stdout/stderr leaks kill the process withSIGTERM."warn": Log the alert box, redact the secret value with its SHA-256 fingerprint, and allow execution to continue."off": Completely disable monitoring for this channel.
exclusions
- Type:
object
exclusions.domains
- Type:
string[] - Default:
[]
NO_PROXY.
exclusions.paths
- Type:
string[] - Default:
[]
entropy
- Type:
object
quiet
- Type:
boolean - Default:
false
true, suppresses the startup banner and immediate per-leak terminal alerts. The final exit summary and report files are still generated.
logFile
- Type:
string | null - Default:
null
envtrap streams structured JSONL events as leaks occur. Can be relative to CWD or an absolute path.
Configuration Recipes
- Production (Strict)
- Development (Permissive)
- CI / Headless Runner
Blocks all network leaks, DNS tunneling, and subprocess leaks:
Validating Your Configuration
Runenvtrap check to validate your envtrap.json file against the schema before running your application:
