Skip to main content

Incident Reports & Auditing

envtrap provides comprehensive auditing and reporting capabilities to help security teams, developers, and compliance engines inspect credential exposure incidents.

1. End-of-Run Report (.envtrap-report.json)

When an application monitored by envtrap terminates, envtrap compiles all intercepted leak events and writes a structured JSON file named .envtrap-report.json in the current working directory.

Report Structure

.envtrap-report.json

Field Definitions


2. Streaming JSONL Event Logs (--log-file)

For long-running microservices, production servers, or SIEM pipelines (such as Datadog, Splunk, or Elastic), waiting for process exit is not practical. Configure logFile in envtrap.json or pass --log-file <path> on the CLI:
Each intercepted leak is immediately appended as a single newline-delimited JSON line:

3. Vulnerability Reporting & Disclosure

If you discover a security vulnerability or bypass within envtrap itself:
Do not open a public GitHub issue. Publicly reporting a security flaw exposes active users before a patch can be deployed.

How to Disclose:

  • Email: Send vulnerability details and minimal reproductions to:
  • Include:
    1. A clear description of the vulnerability.
    2. Minimal reproduction steps or proof-of-concept code.
    3. Affected envtrap versions.
    4. Suggested remediation if available.

Disclosure Timeline:

  • Acknowledgment: Within 24 hours.
  • Severity Assessment: Within 72 hours.
  • Patch & CVE Assignment: Within 14–30 days.