<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>secret</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/410/feed"/>
    <updated>2026-07-28T19:27:52+00:00</updated>
    <id>https://links.biapy.com/guest/tags/410/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13372</id>
            <title type="text"><![CDATA[Kingfisher]]></title>
            <link rel="alternate" href="https://mongodb.github.io/kingfisher/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13372"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Secret Scanner with Live Validation

Detect, validate, and revoke leaked credentials across your codebase, Git history, cloud storage, and developer platforms. Built in Rust by MongoDB. 

- [Kingfisher @ GitHub](https://github.com/mongodb/kingfisher).]]>
            </summary>
            <updated>2026-07-23T05:57:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12902</id>
            <title type="text"><![CDATA[External Secrets Operator]]></title>
            <link rel="alternate" href="https://external-secrets.io/main/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12902"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[External Secrets Operator is a Kubernetes operator that integrates external secret management systems like AWS Secrets Manager, HashiCorp Vault, Google Secrets Manager, Azure Key Vault, IBM Cloud Secrets Manager, CyberArk Secrets Manager, Pulumi ESC and many more. The operator reads information from external APIs and automatically injects the values into a Kubernetes Secret.

- [External Secrets Operator @ GitHub](https://github.com/external-secrets/external-secrets).

Related contents:

- [Discover the External Secret Operator (ESO) OVHcloud Provider to manage your Kubernetes secrets 🎉 @ OVHcloud Blog](https://blog.ovhcloud.com/discover-the-external-secret-operator-eso-ovhcloud-provider-to-manage-your-kubernetes-secrets-%f0%9f%8e%89/).]]>
            </summary>
            <updated>2026-06-03T10:09:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12849</id>
            <title type="text"><![CDATA[Claw Patrol]]></title>
            <link rel="alternate" href="https://clawpatrol.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12849"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The security firewall for agents.

Give agents prod access and still sleep easy

Claw Patrol holds agent credentials, parses their traffic at the wire, and gates actions they take with rules you write, all while keeping an audit log of every action.

- [Claw Patrol @ GitHub](https://github.com/denoland/clawpatrol).]]>
            </summary>
            <updated>2026-05-25T11:52:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12526</id>
            <title type="text"><![CDATA[Keeper]]></title>
            <link rel="alternate" href="https://github.com/agberohq/keeper" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12526"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple Secure Keeper for Secrets.

Keeper is a cryptographic secret store for Go. It encrypts arbitrary byte payloads at rest using Argon2id key derivation and XChaCha20-Poly1305 (default) authenticated encryption, and stores them in an embedded bbolt database.]]>
            </summary>
            <updated>2026-04-13T04:09:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12353</id>
            <title type="text"><![CDATA[layerleak]]></title>
            <link rel="alternate" href="https://github.com/Brumbelow/layerleak" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12353"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[layerleak the Docker Hub Secret Scanner.

Traditional secret scanners often treat a container image as a flat blob or depend on a local Docker daemon. This project is designed around OCI image internals]]>
            </summary>
            <updated>2026-03-28T18:07:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12300</id>
            <title type="text"><![CDATA[Betterleaks]]></title>
            <link rel="alternate" href="https://betterleaks.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12300"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Better Secrets Scanner. Detect Leaked API Keys &amp;amp; Credentials.
 A Better Secrets Scanner built for configurability and speed.

Betterleaks is a tool for detecting secrets like passwords, API keys, and tokens in git repos, files, and whatever else you wanna throw at it via stdin. If you wanna learn more about how the detection engine works check out this blog: [Regex is (almost) all you need](https://lookingatcomputer.substack.com/p/regex-is-almost-all-you-need).

- [Betterleaks @ GitHub](https://github.com/betterleaks/betterleaks).

Related contents:

- [Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks @ aikido](https://www.aikido.dev/blog/betterleaks-gitleaks-successor).]]>
            </summary>
            <updated>2026-03-26T13:38:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12236</id>
            <title type="text"><![CDATA[Nord Stream]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/nord-stream" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12236"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab. 

Related contents:

- [CI/CD secrets extraction, tips and tricks @ Synacktiv](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks).]]>
            </summary>
            <updated>2026-03-23T14:24:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12104</id>
            <title type="text"><![CDATA[OneCLI]]></title>
            <link rel="alternate" href="https://onecli.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12104"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Give your agents access, not your secrets.
The open-source secret vault for AI agents.
 Store once. Inject anywhere. Agents never see the keys. 

Open-source credential vault. Your agents call services and never see a key.

OneCLI is an open-source gateway that sits between your AI agents and the services they call. Instead of baking API keys into every agent, you store credentials once in OneCLI and the gateway injects them transparently. Agents never see the secrets.

- [OneCLI @ GitHub](https://github.com/onecli/onecli).]]>
            </summary>
            <updated>2026-07-24T12:29:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12097</id>
            <title type="text"><![CDATA[enject]]></title>
            <link rel="alternate" href="https://github.com/GreatScott/enject" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12097"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hide .env secrets from prAIng eyes.

secrets live in local encrypted stores (per project) and are injected directly into apps at runtime, never touching disk as plaintext. 

Related contents:

- [Don’t let A.I. read your .env files @ Filip Hric](https://filiphric.com/dont-let-ai-read-your-env-files).]]>
            </summary>
            <updated>2026-03-12T11:16:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12068</id>
            <title type="text"><![CDATA[Lade]]></title>
            <link rel="alternate" href="https://github.com/zifeo/lade" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12068"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automatically load secrets from your preferred vault as environment variables or files, and clear them once your shell command is over. 

Lade (/leɪd/) is a tool allowing you to automatically load secrets from your preferred vault into environment variables or files. It limits the exposure of secrets to the time the command requiring the secrets lives.

Related contents:

- [Lade : injecter les secrets automatiquement avec des hooks shell @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/secrets/lade/).]]>
            </summary>
            <updated>2026-03-09T10:26:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12019</id>
            <title type="text"><![CDATA[CredData (Credential Dataset)]]></title>
            <link rel="alternate" href="https://github.com/Samsung/CredData" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12019"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CredData (Credential Dataset) is a set of files including credentials in open source projects. CredData includes suspicious lines with manual review results and more information such as credential types for each suspicious line.

CredData can be used to develop new tools or improve existing tools. Furthermore, using the benchmark result of the CredData, users can choose a proper tool among open source credential scanning tools according to their use case. We sincerely hope that CredData will help minimize credential leaks.

Related contents:

- [\#66 @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-66).]]>
            </summary>
            <updated>2026-03-05T12:10:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11935</id>
            <title type="text"><![CDATA[git-agecrypt]]></title>
            <link rel="alternate" href="https://github.com/vlaci/git-agecrypt" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11935"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Git integration usable to store encrypted secrets in the git repository while having the plaintext available in the working tree. An alternative to git-crypt using age instead of GPG.

Do not use this tool unless you understand the security implications. I am by no mean a security expert and this code hasn&amp;#039;t been audited. Use at your own risk.]]>
            </summary>
            <updated>2026-02-27T06:41:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11933</id>
            <title type="text"><![CDATA[krops (krebs operations)]]></title>
            <link rel="alternate" href="https://github.com/krebs/krops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11933"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[krops is a lightweight toolkit to deploy NixOS systems, remotely or locally.

-  [krops @ GitHub](https://github.com/krebs/krops).]]>
            </summary>
            <updated>2026-02-27T06:38:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11929</id>
            <title type="text"><![CDATA[Titus]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/titus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11929"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 459 detection rules with live credential validation.]]>
            </summary>
            <updated>2026-02-26T11:16:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11849</id>
            <title type="text"><![CDATA[Swarm External Secrets]]></title>
            <link rel="alternate" href="https://sugar-org.github.io/swarm-external-secrets/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11849"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Docker Swarm secrets plugin that integrates with multiple secret management providers including HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and OpenBao.

- [Swarm External Secrets @ GitHub](https://github.com/sugar-org/swarm-external-secrets).]]>
            </summary>
            <updated>2026-02-17T15:42:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11589</id>
            <title type="text"><![CDATA[Dotenv Mask Editor]]></title>
            <link rel="alternate" href="https://github.com/xinbenlv/dotenv-mask-editor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11589"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure visual editor for .env files that masks sensitive secrets while allowing easy editing.

Dotenv Mask Editor provides a table-based interface for .env files. It is designed to reduce the accidental exposure of sensitive values by masking strings that meet a length threshold. All processing is done locally within your editor.

Related contents:

- [Dotenv Mask Editor - Fini les clés API à l&amp;#039;air libre @ Korben :fr:](https://korben.info/dotenv-mask-editor.html).]]>
            </summary>
            <updated>2026-03-16T09:38:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11567</id>
            <title type="text"><![CDATA[lockenv]]></title>
            <link rel="alternate" href="https://github.com/illarion/lockenv" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11567"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple, CLI-friendly secret storage that lets you safely commit encrypted secrets to version control.

 Simple, password-based encrypted vault for .env and infrastructure secrets. Like git-crypt or sops, but dramatically simpler. Ideal for small teams and IaC workflows 

lockenv provides a secure way to store sensitive files (like .env files, configuration files, certificates) in an encrypted .lockenv file that can be safely committed to your repository. Files are encrypted using a password-derived key and can be easily extracted when needed.]]>
            </summary>
            <updated>2026-01-22T16:44:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11524</id>
            <title type="text"><![CDATA[envmap]]></title>
            <link rel="alternate" href="https://github.com/BinSquare/envmap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11524"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ENV management tool, consolidate and manage .env and env variables. 

Related contents:

- [Envmap - Fini les fichiers .env qui traînent et finissent sur GitHub @ Korben :fr:](https://korben.info/envmap-secrets-sans-fichier-env-disque-github-leaks.html).]]>
            </summary>
            <updated>2026-01-19T08:24:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11144</id>
            <title type="text"><![CDATA[agenix]]></title>
            <link rel="alternate" href="https://github.com/ryantm/agenix" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11144"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[age-encrypted secrets for NixOS and Home manager.

agenix is a small and convenient Nix library for securely managing and deploying secrets using common public-private SSH key pairs: You can encrypt a secret (password, access-token, etc.) on a source machine using a number of public SSH keys, and deploy that encrypted secret to any another target machine that has the corresponding private SSH key of one of those public keys.

Related contents:

- [Public Dotfiles, Private Secrets: My Nix OS Docker Workflow @ Tymscar](https://blog.tymscar.com/posts/nixosdockerwithsecrets/)]]>
            </summary>
            <updated>2025-12-01T13:30:12+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11021</id>
            <title type="text"><![CDATA[github-update-secret]]></title>
            <link rel="alternate" href="https://github.com/mheap/github-update-secret" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11021"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Update a GitHub Secret in all your repos at the same time.

This CLI tool allows you to update the value of a GitHub Secret on multiple repositories at once. This is useful if you&amp;#039;re using a user account and not an org, as users do not have the concept of user level secrets.

Related contents:

- [Automated NPM secret rotation in GitHub Actions @ Michael Heap](https://michaelheap.com/rotate-all-npm-tokens-github-actions/).]]>
            </summary>
            <updated>2025-11-20T12:41:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11020</id>
            <title type="text"><![CDATA[Mojo-V]]></title>
            <link rel="alternate" href="https://github.com/toddmaustin/mojo-v" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11020"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A RISC-V instruction set extension for privacy-oriented programming. Mojo-V allows programmers to write software that computes on data that no software or person can see, except the data owner. Mojo-V implements this novel form of secret computation using simple extensions to a RISC-V CPU.]]>
            </summary>
            <updated>2025-11-20T12:12:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10975</id>
            <title type="text"><![CDATA[BackVault]]></title>
            <link rel="alternate" href="https://github.com/mvfc/backvault" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10975"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Docker container to backup Bitwarden/Vaultwarden vaults to password protected json files.

BackVault is a lightweight Dockerized service that periodically backs up your Bitwarden or Vaultwarden vaults into password-protected encrypted files. It’s designed for hands-free, secure, and automated backups using the official Bitwarden CLI.]]>
            </summary>
            <updated>2025-11-16T16:12:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10840</id>
            <title type="text"><![CDATA[fnox]]></title>
            <link rel="alternate" href="https://fnox.jdx.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10840"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fort Knox for your secrets.  encrypted/remote secret manager.

Manage secrets with encryption or cloud providers - or both!

- [🔐 fnox @ GitHub](https://github.com/jdx/fnox).

Related contents:

- [Fnox - Le Fort Knox de vos secrets de dev @ Korben :fr:](https://korben.info/fnox-gestionnaire-de-secrets-dev.html).
- [Mise-en-place &amp;amp; Fnox : mon setup de gestion multi-projets @ Rémi Tech Notes :fr:](https://www.vrchr.fr/posts/2026/04/28/mise-en-place-fnox-setup-multi-projets/).]]>
            </summary>
            <updated>2026-04-29T06:48:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10786</id>
            <title type="text"><![CDATA[&amp;quot;Sealed Secrets&amp;quot; for Kubernetes]]></title>
            <link rel="alternate" href="https://github.com/bitnami-labs/sealed-secrets" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10786"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Kubernetes controller and tool for one-way encrypted Secrets.

Problem: &amp;quot;I can manage all my K8s config in git, except Secrets.&amp;quot;
Solution: Encrypt your Secret into a SealedSecret, which is safe to store - even inside a public repository. The SealedSecret can be decrypted only by the controller running in the target cluster and nobody else (not even the original author) is able to obtain the original Secret from the SealedSecret.

Related contents:

- [GitOps architecture, patterns and anti-patterns @ Platform Engineering](https://platformengineering.org/blog/gitops-architecture-patterns-and-anti-patterns).]]>
            </summary>
            <updated>2026-03-04T12:41:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10163</id>
            <title type="text"><![CDATA[DELE.TO]]></title>
            <link rel="alternate" href="https://dele.to/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10163"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure Credential Sharing.

Share sensitive credentials and secrets securely with client-side AES-256 encryption, zero-knowledge architecture, and automatic self-destruction.

- [DELE.TO @ GitHub](https://github.com/dele-to/dele-to).]]>
            </summary>
            <updated>2025-09-12T11:49:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10004</id>
            <title type="text"><![CDATA[Have I Been Pwned]]></title>
            <link rel="alternate" href="https://haveibeenpwned.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10004"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Check if your email address has been exposed in a data breach.

Related contents:

- [Troy Hunt - L&amp;#039;histoire du créateur de Have I Been Pwned @ Korben :fr:](https://korben.info/troy-hunt-developpeur-chez-pfizer-gardien.html).]]>
            </summary>
            <updated>2025-09-04T12:43:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/243</id>
            <title type="text"><![CDATA[Shoji-nix]]></title>
            <link rel="alternate" href="https://github.com/AdoPi/shoji-nix" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/243"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Bundle and save your SSH keys with Nix.
This flake provides a way to encrypt and bundle your SSH keys and SSH config in a readable format!

Shoji-Nix is a Nix flake designed to manage and securely store your SSH keys. With Shoji-Nix, you can bundle your SSH configuration and .ssh folder into a YAML file which can then be encrypted and saved in your repository.]]>
            </summary>
            <updated>2025-10-21T19:00:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/272</id>
            <title type="text"><![CDATA[SecretSpec]]></title>
            <link rel="alternate" href="https://secretspec.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/272"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Declarative secrets, every environment, any provider.

SecretSpec separates the declaration of what secrets an application needs from where they are stored, enabling portable applications that work across different secret storage backends without code changes.

- [SecretSpec @ GitHub](https://github.com/cachix/secretspec).

Related contents:

- [Announcing SecretSpec: Declarative Secrets Management @ devenv](https://devenv.sh/blog/2025/07/21/announcing-secretspec-declarative-secrets-management/).]]>
            </summary>
            <updated>2025-11-20T13:39:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/393</id>
            <title type="text"><![CDATA[varlock]]></title>
            <link rel="alternate" href="https://varlock.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/393"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Use @decorator comments in your .env file(s) to create a declarative schema for your config and a new function call syntax to securely load secrets from external sources. 

Varlock is our tool that uses this parser to actually load your .env files, and then applies the schema that you have defined. It is a CLI, library, and will communicate with a native Mac application that enables using biometric auth to securely encrypt your local secrets.

- [varlock @ GitHub](https://github.com/dmno-dev/varlock).]]>
            </summary>
            <updated>2026-01-20T15:31:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/408</id>
            <title type="text"><![CDATA[SOPS: Secrets OPerationS]]></title>
            <link rel="alternate" href="https://getsops.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/408"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SOPS is an editor of encrypted files that supports YAML, JSON, ENV, INI and BINARY formats and encrypts with AWS KMS, GCP KMS, Azure Key Vault, age, and PGP

- [SOPS @ GitHub](https://github.com/getsops/sops).

Related contents:

- [pre-commit-hook-ensure-sops @ GitHub](https://github.com/yuvipanda/pre-commit-hook-ensure-sops).
- [Managing Kubernetes Secrets with Mozilla SOPS and AGE @ Cyril Baah&amp;#039;s Medium](https://medium.com/@cbaah123/managing-kubernetes-secrets-with-mozilla-sops-and-age-780c84e6ec5e).]]>
            </summary>
            <updated>2026-03-06T07:15:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/440</id>
            <title type="text"><![CDATA[Force Push Secret Scanner]]></title>
            <link rel="alternate" href="https://github.com/trufflesecurity/force-push-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/440"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan for secrets in dangling commits on GitHub using GH Archive data. 

This tool scans for secrets in dangling (dereferenced) commits on GitHub created by force push events. A force push occurs when developers overwrite commit history, which often contains mistakes, like hard-coded credentials. This project relies on archived force push event data in the GHArchive to identify the relevant commits.

Related contents:

- [Guest Post: How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets @ Truffle Security](https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets).
- [Comment un hacker a scanné tous les commits &amp;quot;oops&amp;quot; de GitHub et trouvé 25k$ de secrets @ Korben :fr:](https://korben.info/hacker-scanne-tous-commits-oops-github.html).]]>
            </summary>
            <updated>2025-08-28T17:10:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/475</id>
            <title type="text"><![CDATA[Kingfisher]]></title>
            <link rel="alternate" href="https://github.com/mongodb/kingfisher" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/475"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Kingfisher is a blazingly fast secret‑scanning and validation tool built in Rust. It combines Intel’s hardware‑accelerated Hyperscan regex engine with language‑aware parsing via Tree‑Sitter, and ships with hundreds of built‑in rules to detect, validate, and triage secrets before they ever reach production.

Related contents:

- [MongoDB Launches an Open Source Real-Time Secret Scanner @ It&amp;#039;s FOSS News](https://news.itsfoss.com/mongodb-launches-kingfisher/).]]>
            </summary>
            <updated>2025-09-29T05:52:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/869</id>
            <title type="text"><![CDATA[🔐 OTI - One Time Information]]></title>
            <link rel="alternate" href="https://oti.karacabay.com/share" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/869"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[One-Time Information Sharing.Encrypted Secret Sharing.

Share sensitive information securely with a link that can only be viewed once. 

- [🔐 OTI - One Time Information @ GitHub](https://github.com/oguzhankrcb/OTI).]]>
            </summary>
            <updated>2025-08-28T18:22:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/935</id>
            <title type="text"><![CDATA[Teller]]></title>
            <link rel="alternate" href="https://github.com/tellerops/teller" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/935"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cloud native secrets management for developers - never leave your command line for secrets. 

Never leave your terminal to use secrets while developing, testing, and building your apps.

Instead of custom scripts, tokens in your .zshrc files, visible EXPORTs in your bash history, misplaced .env.production files and more around your workstation -- just use teller and connect it to any vault, key store, or cloud service you like (Teller support Hashicorp Vault, AWS Secrets Manager, Google Secret Manager, and many more).]]>
            </summary>
            <updated>2025-08-28T18:34:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1046</id>
            <title type="text"><![CDATA[Ansible Vault password input with Bitwarden CLI]]></title>
            <link rel="alternate" href="https://github.com/guiand888/ansible-vault-bitwarden" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1046"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Manage ansible-vault passwords securely with Bitwarden CLI .]]>
            </summary>
            <updated>2025-08-28T18:51:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1343</id>
            <title type="text"><![CDATA[🐱 PurrCrypt 🐶]]></title>
            <link rel="alternate" href="https://github.com/vxfemboy/purrcrypt" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1343"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fur-ociously Secure, Paw-sitively Adorable!

The purr-fect way to keep your secrets fur-ever safe, straight from the meow-th of your computer to your fur-ends&amp;#039; paws!
A fur-ociously secure encryption tool that encodes your secrets as adorable cat and dog sounds, using real elliptic curve cryptography with a playful disguise.]]>
            </summary>
            <updated>2025-08-28T19:40:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1477</id>
            <title type="text"><![CDATA[External Secrets Operator]]></title>
            <link rel="alternate" href="https://external-secrets.io/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1477"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as Kubernetes Secrets. 

- [External Secrets Operator @ GitHub](https://github.com/external-secrets/external-secrets).

Related contents:

- [(Almost) Every infrastructure decision I endorse or regret after 4 years running infrastructure at a startup @ Jack&amp;#039;s home on the web](https://cep.dev/posts/every-infrastructure-decision-i-endorse-or-regret-after-4-years-running-infrastructure-at-a-startup/).
- [How Maintainer Burnout Is Causing a Kubernetes Security Disaster @ The New Stack](https://thenewstack.io/how-maintainer-burnout-is-causing-a-kubernetes-security-disaster/).
- [GitOps architecture, patterns and anti-patterns @ Platform Engineering](https://platformengineering.org/blog/gitops-architecture-patterns-and-anti-patterns).
- [Discover the External Secret Operator (ESO) OVHcloud Provider to manage your Kubernetes secrets 🎉 @ OVHcloud](https://blog.ovhcloud.com/discover-the-external-secret-operator-eso-ovhcloud-provider-to-manage-your-kubernetes-secrets-%f0%9f%8e%89/).]]>
            </summary>
            <updated>2026-04-14T08:11:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1618</id>
            <title type="text"><![CDATA[Novops]]></title>
            <link rel="alternate" href="https://novops.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cross-platform secret &amp;amp; config manager for development and CI environments 

Novops, the universal secret and configuration manager for development, applications and CI.

- [Novops @ GitHub](https://github.com/PierreBeucher/novops).

Related contents:

- [Novops facilite l&amp;#039;accès aux secrets @ DevSecOps :fr:](https://blog.stephane-robert.info/post/novops-secrets/).]]>
            </summary>
            <updated>2025-08-28T20:25:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1634</id>
            <title type="text"><![CDATA[OTS - One Time Secrets]]></title>
            <link rel="alternate" href="https://ots.fyi/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1634"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser 

ots is a one-time-secret sharing platform. The secret is encrypted with a symmetric 256bit AES encryption in the browser before being sent to the server. Afterwards an URL containing the ID of the secret and the password is generated. The password is never sent to the server so the server will never be able to decrypt the secrets it delivers with a reasonable effort. Also the secret is immediately deleted on the first read.

- [OTS - One Time Secrets @ GitHub](https://github.com/Luzifer/ots).]]>
            </summary>
            <updated>2025-08-28T20:28:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2242</id>
            <title type="text"><![CDATA[Seedkeeper]]></title>
            <link rel="alternate" href="https://seedkeeper.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2242"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure password &amp;amp; seedphrase manager on smartcard 🔐

Seedkeeper lets you effortlesly store all your passwords and protect your digital life so you can sleep on both ears.

Source: [SeedKeeper - La carte à puce qui sécurise vos mots de passe @ Korben :fr:](https://korben.info/seedkeeper-carte-securisee-sauvegarde-crypto.html).]]>
            </summary>
            <updated>2025-08-28T22:09:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2456</id>
            <title type="text"><![CDATA[Hemmelig.app]]></title>
            <link rel="alternate" href="https://hemmelig.app/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2456"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Paste a password, confidential message, or private data.
Keep your sensitive information out of chat logs, emails, and more with encrypted secrets. 

 Hemmelig is a encrypted sharing platform that enables secure transmission of sensitive information. All encryption occurs client-side using TweetNaCl, ensuring your data remains encrypted before it reaches our servers. The platform supports both personal and organizational use cases, with features like IP restrictions, expiration controls, and optional password protection. Whether you&amp;#039;re sharing credentials, sensitive messages, or confidential files, Hemmelig strives to ensure your data remains private and secure. 

- [Hemmelig.app @ GitHub](https://github.com/HemmeligOrg/Hemmelig.app).]]>
            </summary>
            <updated>2025-08-28T22:45:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2468</id>
            <title type="text"><![CDATA[Dotenv]]></title>
            <link rel="alternate" href="https://www.dotenv.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2468"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secrets for developers.

Dotenv is a zero-dependency module that loads environment variables from a .env file into process.env. Storing configuration in the environment separate from code is based on The Twelve-Factor App methodology.

- [Dotenv @ GitHub](https://github.com/motdotla/dotenv).]]>
            </summary>
            <updated>2025-08-28T22:48:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2707</id>
            <title type="text"><![CDATA[Squealer]]></title>
            <link rel="alternate" href="https://github.com/owenrumney/squealer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2707"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Telling tales on you for leaking secrets!.

Squealer scans a git repository or filesystem for secrets that are being leaked deep within the commit history.]]>
            </summary>
            <updated>2025-08-28T23:27:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2752</id>
            <title type="text"><![CDATA[JWT Secret Generator]]></title>
            <link rel="alternate" href="https://jwtsecret.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2752"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Generate JWT Secrets Online

Quickly generate secure JWT secrets with a single click.]]>
            </summary>
            <updated>2025-08-28T23:35:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2768</id>
            <title type="text"><![CDATA[Talisman]]></title>
            <link rel="alternate" href="https://thoughtworks.github.io/talisman/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2768"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Using a pre-commit hook, Talisman validates the outgoing changeset for things that look suspicious — such as tokens, passwords, and private keys. 

Talisman is a tool that scans git changesets to ensure that potential secrets or sensitive information do not leave the developer&amp;#039;s workstation.
It validates the outgoing changeset for things that look suspicious - such as potential SSH keys, authorization tokens, private keys etc.

- [Talisman @ GitHub](https://github.com/thoughtworks/talisman).]]>
            </summary>
            <updated>2025-08-28T23:37:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2801</id>
            <title type="text"><![CDATA[GitDorker]]></title>
            <link rel="alternate" href="https://github.com/obheda12/GitDorker" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2801"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Python program to scrape secrets from GitHub through usage of a large repository of dorks. 

GitDorker is a tool that utilizes the GitHub Search API and an extensive list of GitHub dorks that I&amp;#039;ve compiled from various sources to provide an overview of sensitive information stored on github given a search query.

The Primary purpose of GitDorker is to provide the user with a clean and tailored attack surface to begin harvesting sensitive information on GitHub. GitDorker can be used with additional tools such as GitRob or Trufflehog on interesting repos or users discovered from GitDorker to produce best results.]]>
            </summary>
            <updated>2025-08-28T23:43:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2818</id>
            <title type="text"><![CDATA[Whispr]]></title>
            <link rel="alternate" href="https://github.com/narenaryan/whispr" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2818"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A multi-vault secret injection tool for safely injecting secrets into app environment.

Whispr (Pronounced as whisper) is a CLI tool to safely inject secrets from your favorite secret vault (Ex: AWS Secrets Manager, Azure Key Vault etc.) into your app&amp;#039;s environment. This is very useful for enabling secure local software development.]]>
            </summary>
            <updated>2025-08-28T23:46:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2904</id>
            <title type="text"><![CDATA[Flask-Vault]]></title>
            <link rel="alternate" href="https://github.com/multiversecoder/Flask-Vault" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2904"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Flask-Vault is a robust library that empowers Flask applications to securely store and manage sensitive credentials. It provides a set of CLI commands for storing secrets using AES-GCM symmetric encryption, ensuring that vital information like API keys and database credentials remain protected. 

Flask-Vault provides several cli commands and Python functions to store secrets that you do not want to keep in the clear, using symmetric encryption with AES-GCM. These commands and functions allow you to safely read/write very important credentials such as API keys, database credentials, etc.]]>
            </summary>
            <updated>2025-08-29T00:01:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2933</id>
            <title type="text"><![CDATA[detect-secrets]]></title>
            <link rel="alternate" href="https://github.com/Yelp/detect-secrets" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2933"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An enterprise friendly way of detecting and preventing secrets in code. 

detect-secrets is an aptly named module for (surprise, surprise) detecting secrets within a code base.]]>
            </summary>
            <updated>2026-07-01T15:03:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2934</id>
            <title type="text"><![CDATA[GitGuardian]]></title>
            <link rel="alternate" href="https://www.gitguardian.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2934"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Git Security Scanning &amp;amp; Secrets Detection.

- [ggshield @ GitHub](https://github.com/GitGuardian/ggshield).
- [Doctolib divise par deux ses incidents de sécurité liés aux secrets@ LeMagIT :fr:](https://www.lemagit.fr/etude/Doctolib-divise-par-deux-ses-incidents-de-securite-lies-aux-secrets).]]>
            </summary>
            <updated>2025-08-29T00:06:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3123</id>
            <title type="text"><![CDATA[Doppler]]></title>
            <link rel="alternate" href="https://www.doppler.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3123"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Centralized Cloud-Based Secrets Management Platform.

Securely manage, orchestrate, and govern secrets at scale with Doppler’s developer-first cloud hosted platform.

- [Doppler CLI @ GitHub](https://github.com/DopplerHQ/cli).

Related contents:

- [10 CLI apps that have actually improved the way I work in the terminal @ Dreams of Code&amp;#039;s YouTube](https://www.youtube.com/watch?v=EJ6uvqhKR4M).]]>
            </summary>
            <updated>2025-09-22T06:14:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3744</id>
            <title type="text"><![CDATA[♾ Infisical]]></title>
            <link rel="alternate" href="https://infisical.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3744"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Secret Management. All-in-one platform to securely manage application configuration and secrets across your team and infrastructure.

 ♾ Infisical is the open-source secret management platform: Sync secrets across your team/infrastructure, prevent secret leaks, and manage internal PKI.

- [Infisical @ GitHub](https://github.com/Infisical/infisical).]]>
            </summary>
            <updated>2025-08-29T02:21:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3870</id>
            <title type="text"><![CDATA[TruffleHog]]></title>
            <link rel="alternate" href="https://trufflesecurity.com/trufflehog" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3870"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find and verify secrets. Find leaked credentials.

TruffleHog is the most powerful secrets Discovery, Classification, Validation, and Analysis tool. In this context secret refers to a credential a machine uses to authenticate itself to another machine. This includes API keys, database passwords, private encryption keys, and more...

- [TruffleHog @ GitHub](https://github.com/trufflesecurity/trufflehog).

Related contents:

- [Keeping Secrets Out of Logs @ allan.reyes.sh](https://allan.reyes.sh/posts/keeping-secrets-out-of-logs/).
- [How Security Tool Misuse Is Reshaping Cloud Compromise @ Qualys](https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise).]]>
            </summary>
            <updated>2026-03-05T12:17:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3958</id>
            <title type="text"><![CDATA[Tang]]></title>
            <link rel="alternate" href="https://github.com/latchset/tang" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3958"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Tang binding daemon.

Tang is a server for binding data to network presence.

This sounds fancy, but the concept is simple. You have some data, but you only want it to be available when the system containing the data is on a certain, usually secure, network. This is where Tang comes in.

- [Clevis/Tang: unattended boot of an encrypted NixOS system @ FOSDEM](https://fosdem.org/2024/schedule/event/fosdem-2024-3044-clevis-tang-unattended-boot-of-an-encrypted-nixos-system/).
- [Clevis &amp;amp; Tang on NixOS](https://camillemondon.com/talks/fosdem24-clevis/)
- [Episode 572: Data Security Only a Maniac Could Love @ Linux Unplugged](https://linuxunplugged.com/572).]]>
            </summary>
            <updated>2025-08-29T02:57:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4119</id>
            <title type="text"><![CDATA[Gitleaks]]></title>
            <link rel="alternate" href="https://gitleaks.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4119"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Gitleaks is a fast, light-weight, portable, and open-source secret scanner for git repositories, files, and directories. 

- [Gitleaks @ GitHub](https://github.com/gitleaks/gitleaks).

Related contents:

- [Gitleaks : Evitez le vol de secrets sur Git ! @ Geeek.org :fr:](https://www.geeek.org/securiser-depots-git-gitleaks/).
- [I&amp;#039;m Switching to Python and Actually Liking It @ César Soto Valero](https://www.cesarsotovalero.net/blog/i-am-switching-to-python-and-actually-liking-it.html).]]>
            </summary>
            <updated>2025-08-29T03:23:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4601</id>
            <title type="text"><![CDATA[Magic Wormhole]]></title>
            <link rel="alternate" href="https://github.com/magic-wormhole/magic-wormhole" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4601"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[get things from one computer to another, safely.

This package provides a library and a command-line tool named `wormhole`, which makes it possible to get arbitrary-sized files and directories (or short pieces of text) from one computer to another. The two endpoints are identified by using identical &amp;quot;wormhole codes&amp;quot;: in general, the sending machine generates and displays the code, which must then be typed into the receiving machine.

- [Magic Wormhole @ Read the Docs](https://magic-wormhole.readthedocs.io/).

Sources:

- [Wormhole: Transférer des Secrets @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/secrets/wormhole/)
- [PGP - Je ne chiffre plus les emails @ 9x0rg :fr:](https://9x0rg.com/posts/tech/pgp-je-ne-chiffre-plus-les-emails/).]]>
            </summary>
            <updated>2025-08-29T04:43:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4679</id>
            <title type="text"><![CDATA[Password Pusher]]></title>
            <link rel="alternate" href="https://pwpush.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4679"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Securely Send a Password.

 🔐 An application to securely communicate passwords over the web. Passwords automatically expire after a certain number of views and/or time has passed. Track who, what and when.

- [Password Pusher @ GitHub](https://github.com/pglombardo/PasswordPusher).
- [6 outils de FOU pour les DEVS 🤯 @ YoanDev&amp;#039;s YouTube](https://www.youtube.com/watch?v=x0niOhjzkxw).]]>
            </summary>
            <updated>2025-08-29T04:56:50+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4684</id>
            <title type="text"><![CDATA[OpenBao]]></title>
            <link rel="alternate" href="https://openbao.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4684"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

- [OpenBao @ GitHub](https://github.com/openbao/openbao).

Related contents:

- [OpenBao (Hashicorp Vault Fork effort) FAQ @ LF Edge](https://wiki.lfedge.org/display/OH/OpenBao+%28Hashicorp+Vault+Fork+effort%29+FAQ).
- [Open source forkers stick an OpenBao in the oven @ The Register](https://www.theregister.com/2023/12/08/hashicorp_openbao_fork/).
- [Vault on Kubernetes using OpenBao @ nanibot.net](https://nanibot.net/posts/vault/).
- [Vault SSH : accès sécurisé aux serveurs @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/secrets/hashicorp-vault/ssh-secrets/).
- [Monitor HCP Vault Dedicated Audit Logs with SigNoz @ SigNoz](https://signoz.io/docs/integrations/outposts/hcp-vault/).]]>
            </summary>
            <updated>2026-07-06T11:36:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4712</id>
            <title type="text"><![CDATA[Sealed Secrets]]></title>
            <link rel="alternate" href="https://sealed-secrets.netlify.app/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4712"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sealed Secrets provides declarative Kubernetes Secret Management in a secure way. Since the Sealed Secrets are encrypted, they can be safely stored in a code repository. This enables an easy to implement GitOps flow that is very popular among the OSS community.

- [Sealed Secrets @ GitHub](https://github.com/bitnami-labs/sealed-secrets).
- [Chiffrer ses YAML avec Sealed Secrets @ Une Tasse de Café](https://une-tasse-de.cafe/blog/sealed-secrets/).]]>
            </summary>
            <updated>2025-08-29T05:02:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4737</id>
            <title type="text"><![CDATA[Has My Secret Leaked?]]></title>
            <link rel="alternate" href="https://www.gitguardian.com/hasmysecretleaked" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4737"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Leak Detection In The DevOps Pipeline

- [Avec le service gratuit « Has My Secret Leaked? », vérifiez si vos secrets ont fuité sur GitHub ! @ IT-Connect.fr :fr:](https://www.it-connect.fr/verifier-fuite-secrets-github-has-my-secret-leaked-gratuit/).]]>
            </summary>
            <updated>2025-08-29T05:07:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4769</id>
            <title type="text"><![CDATA[SOPS]]></title>
            <link rel="alternate" href="https://github.com/getsops/sops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4769"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple and flexible tool for managing secrets.

SOPS is an editor of encrypted files that supports YAML, JSON, ENV, INI and BINARY formats and encrypts with AWS KMS, GCP KMS, Azure Key Vault, age, and PGP.

- [ SOPS la solution de gestion de secret DevOps ? @ DamyR :fr:](https://www.damyr.fr/posts/sops/).]]>
            </summary>
            <updated>2025-08-29T05:11:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6939</id>
            <title type="text"><![CDATA[Vault by HashiCorp]]></title>
            <link rel="alternate" href="https://www.vaultproject.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6939"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Manage Secrets &amp;amp; Protect Sensitive Data

Secure, store and tightly control access to tokens, passwords, certificates, encryption keys for protecting secrets and other sensitive data using a UI, CLI, or HTTP API.

- [Vault @ GitHub](https://github.com/hashicorp/vault).

Related contents:

- [How To Centralize Kubernetes Secrets Management With Vault @ The New Stack](https://thenewstack.io/how-to-centralize-kubernetes-secrets-management-with-vault/).
- [From key sprawl to scalable control: Rethinking SSH access @ Hashicorp&amp;#039;s The Stack](https://www.hashicorp.com/en/blog/from-key-sprawl-to-scalable-control-rethinking-ssh-access).]]>
            </summary>
            <updated>2025-10-15T12:28:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7964</id>
            <title type="text"><![CDATA[Vault by HashiCorp]]></title>
            <link rel="alternate" href="https://developer.hashicorp.com/vault" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7964"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Vault handles leasing, key revocation, key rolling, and auditing. Vault presents a unified API to access multiple backends: HSMs, AWS IAM, SQL databases, raw key/value, and more.

- [HashiCorp Vault @ GitHub](https://github.com/hashicorp/vault).

Related contents:

- [Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault @ Cyata](https://cyata.ai/blog/cracking-the-vault-how-we-found-zero-day-flaws-in-authentication-identity-and-authorization-in-hashicorp-vault/).
- [No More Hardcoded Secrets: Automatic Database Credential Rotation with Vault, AKS and Postgres🔐 @ Poojan Mehta](https://dev.to/poojan18/no-more-hardcoded-secrets-automatic-database-credential-rotation-with-vault-aks-and-postgres-1nmn).]]>
            </summary>
            <updated>2025-09-15T13:26:40+00:00</updated>
        </entry>
    </feed>
