Incident Reports & Auditing
envtrap provides comprehensive auditing and reporting capabilities to help security teams, developers, and compliance engines inspect credential exposure incidents.
1. End-of-Run Report (.envtrap-report.json)
When an application monitored by envtrap terminates, envtrap compiles all intercepted leak events and writes a structured JSON file named .envtrap-report.json in the current working directory.
Report Structure
.envtrap-report.json
Field Definitions
2. Streaming JSONL Event Logs (--log-file)
For long-running microservices, production servers, or SIEM pipelines (such as Datadog, Splunk, or Elastic), waiting for process exit is not practical.
Configure logFile in envtrap.json or pass --log-file <path> on the CLI:
3. Vulnerability Reporting & Disclosure
If you discover a security vulnerability or bypass withinenvtrap itself:
How to Disclose:
- Email: Send vulnerability details and minimal reproductions to:
- Include:
- A clear description of the vulnerability.
- Minimal reproduction steps or proof-of-concept code.
- Affected
envtrapversions. - Suggested remediation if available.
Disclosure Timeline:
- Acknowledgment: Within 24 hours.
- Severity Assessment: Within 72 hours.
- Patch & CVE Assignment: Within 14–30 days.
