EnvGuard is in early development. Security fixes are applied to the latest code on the main branch until stable release support is defined.
Please do not publish suspected vulnerabilities, live credentials, private keys, tokens, secret-bearing files, or sensitive environment details in a public issue.
Use GitHub's private vulnerability reporting feature when it is available for this repository. If private reporting is unavailable, contact the repository owner through the contact method listed on the BLCCoreStudio GitHub profile and include only the minimum information needed to establish a private reporting channel.
We will review actionable reports and coordinate disclosure after a fix is available.
EnvGuard is a local heuristic scanner. A clean result is not a guarantee that a repository is free of secrets, and users should still rotate any credential they believe may have been exposed.