Skip to content

Security: EnvTrap/envtrap-package

Security

SECURITY.md

Security Policy

We take the security of envtrap and the applications protected by it seriously. If you find a security vulnerability, we appreciate your help in disclosing it responsibly.


Supported Versions

Only the latest major version of the envtrap package is actively supported with security updates:

Version Supported
>= 2.0.0 Yes
< 2.0.0 No

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report security issues privately:

  1. Email your findings to the maintainers at vishalpeace07@gmail.com.
  2. Include a detailed description of the vulnerability, steps to reproduce, and a proof-of-concept (PoC) if available.

We will acknowledge your report within 48 hours and work with you to analyze and patch the issue before publishing a public disclosure.

There aren't any published security advisories