Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
_pdp_
3 months ago
|
parent
|
context
|
favorite
| on:
Axios compromised on NPM – Malicious versions drop...
I am not saying this is the reason for this compromise but the sudden explosion of coding assistant like claude code, and tools like openclaw is teaching entire crop of developers (and users) that it is ok to have sensitive credentials .env files.
ptx
3 months ago
[–]
Where would you suggest putting the sensitive credentials?
_pdp_
3 months ago
|
parent
|
next
[–]
Not in .env files next to your code that is exposed to supply chain risks.
jvwww
3 months ago
|
parent
|
prev
[–]
infisical is a great solution
Consider applying for YC's Fall 2026 batch!
Applications
are open till July 27.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: