Skip to content

Security: BinaryBard27/env-check

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue in env-check, please do not open a public issue.

Instead, report it responsibly by emailing:

📧 sherwindmello27@gmail.com

Include:

  • A clear description of the issue
  • Steps to reproduce
  • Potential impact

You will receive an acknowledgment within 72 hours.


Scope

env-check is a configuration validation tool.

It is designed to:

  • Detect common misconfigurations
  • Flag high-risk secrets in environment files
  • Prevent unsafe environment drift

It is NOT designed to:

  • Replace dedicated secret scanners
  • Protect against runtime compromise
  • Secure already leaked credentials

There aren't any published security advisories