If you discover a security issue in env-check, please do not open a public issue.
Instead, report it responsibly by emailing:
Include:
- A clear description of the issue
- Steps to reproduce
- Potential impact
You will receive an acknowledgment within 72 hours.
env-check is a configuration validation tool.
It is designed to:
- Detect common misconfigurations
- Flag high-risk secrets in environment files
- Prevent unsafe environment drift
It is NOT designed to:
- Replace dedicated secret scanners
- Protect against runtime compromise
- Secure already leaked credentials