BehavTest › Reference
Security and privacy
- Suite files are safe to commit: secrets are referenced as
${ENV_VAR}. Resolved values are never written to the database; hard-coded secrets are masked before storing (with a warning). - The database contains your raw inputs and outputs (and pipeline traces), which may be sensitive.
behavtest init git-ignores .behavtest/. Values under secret-looking keys in traces are masked before storing; --no-trace stores none. Compact run files contain no inputs, outputs or traces. - BehavTest contacts only the URLs and providers you configure. There is no telemetry and no update check.
behavtest serve listens on 127.0.0.1 only by default, refuses unknown Host headers (DNS rebinding) and cross-site writes, and writes nothing but your labels. It has no login, so think before exposing it with --host.- Code suites are programs: only run suites you trust.
- Releases are published from GitHub Actions with npm provenance. See SECURITY.md for reporting vulnerabilities.