Vulnerability Disclosure Policy
The envtrap project takes security seriously. If you discover a security vulnerability or potential bypass within envtrap, please follow responsible disclosure practices.
Do not open a public GitHub issue. Publicly reporting a security flaw exposes active users before a patch can be deployed.
How to Report
Send a detailed vulnerability report to:
Please Include:
- Description: A clear description of the vulnerability or bypass.
- Impact: What an attacker could achieve by exploiting this issue.
- Reproduction Steps: A minimal reproduction script or proof-of-concept repository.
- Affected Versions: The specific versions of
envtrap affected.
- Remediation: Suggested code patches if available.
Response Timeline
Scope
In-Scope:
envtrap CLI commands (envtrap run, envtrap check).
- Runtime interceptor hooks (
network, dns, child_process, stdout, stderr).
- In-memory MITM TLS proxy and certificate authority.
- Secret detection engine (false negatives where secrets should have been caught).
Out-of-Scope:
- Vulnerabilities in user application code protected by
envtrap.
- Social engineering or physical attacks against developer machines.