Feed

The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)

via Dev.to·independent coverage, not Tech Spindle reporting
Why this ranksSecurity Practice
33TS ScoreImpact + Innovation, combined
IMPACT35
INNOVATION30

Our take: Token storage best practice using 1Password; useful but not novel.

Why Impact & Innovation? We ask two questions of every story: did this actually change something in the real world (Impact), and is the idea genuinely new (Innovation)? Together, that's the TS Score — not engagement, not who posted it, just what matters and what's new.

Plaintext authentication tokens stored in shell config files like .zshrc and .npmrc can be secured by using the 1Password CLI native plugin system instead.

Read the full article at Dev.to

Opens Dev.to's site in a new tab

ProgrammingOpen SourceTechnologyPublished Aug 6, 6:59 PM
Spin Up

Got a take on "The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)"?

Spin Up drafts a post about this story for you — blog, LinkedIn, or X — in your own voice, sourced and attributed automatically.

Keep exploring

More stories ranked this high

Similar TS Score, same beat — ranked the same way the Top feed ranks everything.

The Tech Spindle loop

Read it. Write your take. Publish it.

This page is one stop in a loop built for anyone whose career depends on staying sharp in tech.

Never miss what matters

Get it delivered, or hear it argued out loud

Same ranking, two formats — read the newsletter in two minutes, or let Harika & Rohan debate it in your ears.

Newsletter

Today's ranked stories, in your inbox.

Daily and weekly editions — no fluff, just what actually scored.

Two AI hosts debate the week's biggest stories.

Listen Now

Ready to publish your own take?

Read it, rank it, write about it, publish it — free during early access.

Request an invite →