Blog / tag
Security
Threat models, plaintext secrets and what an OS credential store does and doesn't protect.
How many plaintext secrets are sitting in your projects folder?
envsec rescue scans a folder for plaintext .env files, reports reused and committed secrets, then moves them into the OS keychain.
Your coding agent can read your .env
Coding agents read files and run commands as you. How a plaintext .env gets exposed, what moving it to the OS keychain fixes, and what it can't.
envsec vs dotenv vs 1Password CLI vs direnv: which one, when
Where dotenv, direnv, 1Password CLI and envsec keep secrets, how they get them into a process, and when each one is the better choice.
What envsec does not protect you from
An honest threat model for envsec: what the OS keychain protects, and what it doesn't: same-user processes, environment variables, argv, metadata, env-file.
Parsing 1y6mo and generating secrets you can't guess
How envsec parses expiry durations like 1y6mo (and why a month is 30 days), and how its secret command avoids modulo bias. With the entropy math.
Sharing secrets with a teammate, the GPG way
How envsec share encrypts a context with GPG, how the receiver imports it with envsec load, and what GPG does and doesn't protect.