<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: devmtk</title><link>https://news.ycombinator.com/user?id=devmtk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 11 Sep 2026 09:06:17 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=devmtk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Why can't you commit a .env file?]]></title><description><![CDATA[
<p>"You can't commit a .env file to Git" is a sentence we've all heard.
Most people accepted it and went on with their lives, using other tools to share environment variables.<p>But the question we should ask is: why can't I commit a .env file to Git?<p>The honest answer isn't that it's bad practice. It's that Git has no permission system below the repository level.
It's all or nothing. You see everything, or
you see nothing. The entire secret-manager industry exists to paper over this one missing primitive.<p>For too long we accepted it as a minor annoyance. That's changed. It isn't a
minor annoyance anymore. It's a real problem.<p>We now have agents monitoring every patch that merges, hunting for security fixes to turn into exploits. The patch itself is the disclosure: it hands
people (and increasingly agents) everything they need to reverse-engineer the fix and hit systems that haven't updated yet. We're in the middle of a security crisis, arguing about where to store files to hide them from attackers.<p>For the last couple of weeks I've been thinking about this: prototyping, trying to find a compelling solution. 
I want to be honest, I have no idea if I found
it. But I think the direction is at least interesting. Permissions, or as I
prefer to call them, capabilities, should live at the content level, not the repo level.
Commit the .env; just scope who's allowed to decrypt it.<p>This is just one of the problems I have with Git(Hub), and honestly, I have no
idea if anything I built is a good solution. I'd love your feedback, or your
rant. If you want to see how I tried to fix it, the repo is here 
(hosted, sarcastically, on GitHub): https://github.com/thaddeus-run/thaddeus</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48904726">https://news.ycombinator.com/item?id=48904726</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 14 Jul 2026 10:42:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48904726</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=48904726</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48904726</guid></item><item><title><![CDATA[Show HN: I made a briefing document generator based on your Questionary]]></title><description><![CDATA[
<p>I wanted an easy briefing generator—nothing from AI. Don’t get me wrong—I’m a fan of AI, but I wanted something that really fits.<p>I created as many Templates as I needed myself. I got a little crazy with all my Templates for the PDF versions. And did a little bit of overengineering for a questionnaire. I made it free and I hope it makes your lives just a little bit easier.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43599726">https://news.ycombinator.com/item?id=43599726</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Sun, 06 Apr 2025 07:57:11 +0000</pubDate><link>https://BriefFast.com</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=43599726</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43599726</guid></item><item><title><![CDATA[New comment by devmtk in "Apple’s Darwin OS and XNU Kernel Deep Dive"]]></title><description><![CDATA[
<p>oh interesting</p>
]]></description><pubDate>Sun, 06 Apr 2025 07:55:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=43599717</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=43599717</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43599717</guid></item><item><title><![CDATA[New comment by devmtk in "Show HN: IWyvern – AWS Infrastructure AI Assistant"]]></title><description><![CDATA[
<p>Seems interesting. But I think it is unnecessary for me. Cause I don't have a use case. But good luck!</p>
]]></description><pubDate>Wed, 02 Apr 2025 19:53:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=43560795</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=43560795</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43560795</guid></item><item><title><![CDATA[New comment by devmtk in "Hacking the call records of millions of Americans"]]></title><description><![CDATA[
<p>Crazy that this is possible at such a giant like Verizon. But it seems to happen more often than before.</p>
]]></description><pubDate>Wed, 02 Apr 2025 19:50:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=43560764</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=43560764</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43560764</guid></item><item><title><![CDATA[New comment by devmtk in "Show HN: A Chrome extension to give you back control over short-form videos"]]></title><description><![CDATA[
<p>Thank you for that. Helps a lot!</p>
]]></description><pubDate>Wed, 02 Apr 2025 19:48:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=43560749</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=43560749</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43560749</guid></item><item><title><![CDATA[Show HN: Doslint – A Platform for Paid Developer Support]]></title><description><![CDATA[
<p>Hey HN,<p>We're indie developers, and like many of you, we're juggling countless tasks: debugging, learning new frameworks, implementing features, and troubleshooting mysterious bugs.<p>So we built Doslint, a platform where you can get and offer paid support directly from other devs. The idea is simple:<p>• Need help? Pay a small fee to an expert and save hours of frustration.<p>• Have expertise? Offer your skills and get paid.<p>We created this after hitting roadblocks in our own projects, when we lacked the time or energy to wade through documentation or Stack Overflow. We wanted something lighter than full consulting just quick, direct, no strings attached support.<p>We built Doslint as a community platform for developers helping developers. It's completely free to use—we don't take any commission. You only pay the developer who helps you.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42985144">https://news.ycombinator.com/item?id=42985144</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 08 Feb 2025 18:46:50 +0000</pubDate><link>https://doslint.com</link><dc:creator>devmtk</dc:creator><comments>https://news.ycombinator.com/item?id=42985144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42985144</guid></item></channel></rss>