Skip to main content

Vulnerability Disclosure Policy

The envtrap project takes security seriously. If you discover a security vulnerability or potential bypass within envtrap, please follow responsible disclosure practices.
Do not open a public GitHub issue. Publicly reporting a security flaw exposes active users before a patch can be deployed.

How to Report

Send a detailed vulnerability report to:

Please Include:

  1. Description: A clear description of the vulnerability or bypass.
  2. Impact: What an attacker could achieve by exploiting this issue.
  3. Reproduction Steps: A minimal reproduction script or proof-of-concept repository.
  4. Affected Versions: The specific versions of envtrap affected.
  5. Remediation: Suggested code patches if available.

Response Timeline


Scope

In-Scope:

  • envtrap CLI commands (envtrap run, envtrap check).
  • Runtime interceptor hooks (network, dns, child_process, stdout, stderr).
  • In-memory MITM TLS proxy and certificate authority.
  • Secret detection engine (false negatives where secrets should have been caught).

Out-of-Scope:

  • Vulnerabilities in user application code protected by envtrap.
  • Social engineering or physical attacks against developer machines.