We take the security of envtrap and the applications protected by it seriously. If you find a security vulnerability, we appreciate your help in disclosing it responsibly.
Only the latest major version of the envtrap package is actively supported with security updates:
| Version | Supported |
|---|---|
| >= 2.0.0 | Yes |
| < 2.0.0 | No |
Please do not open a public GitHub issue for security vulnerabilities.
Instead, report security issues privately:
- Email your findings to the maintainers at vishalpeace07@gmail.com.
- Include a detailed description of the vulnerability, steps to reproduce, and a proof-of-concept (PoC) if available.
We will acknowledge your report within 48 hours and work with you to analyze and patch the issue before publishing a public disclosure.