For fifteen years the .env file has been the most convenient lie in web development: a plaintext file full of production-grade credentials, kept safe by the single assumption that only you would ever read your own disk. That assumption is now false, and the fix is less dramatic than it sounds.




