惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园_首页
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
Tailwind CSS Blog
Stack Overflow Blog
Stack Overflow Blog
N
Netflix TechBlog - Medium
T
The Blog of Author Tim Ferriss
U
Unit 42
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
博客园 - Franky
博客园 - 聂微东

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
I built a CLI that scans, validates and audits your .env ...
Hosaina Yirg · 2026-05-05 · via DEV Community

Hosaina Yirgalem

Every dev team has lost hours to .env problems.

A missing variable breaks a deploy.
An API key gets committed to Git.
A new teammate spends half a day figuring out which variables they need.
Nobody documented anything.

I built Razify to make all of that stop happening.


What is Razify?

Razify is a single binary CLI tool for .env file management.
It diffs, scans, validates, documents, and audits your environment
variables — all from your terminal.

  • No cloud account
  • No tracking
  • No Go installation required

Works with Node.js, Python, Ruby, Laravel, Rails — anything that uses .env files.


What it does

🔍 Secret scanning

   razify scan .env

Enter fullscreen mode Exit fullscreen mode

Detects leaked secrets using 80+ regex patterns combined with
Shannon entropy analysis to catch what pattern matching alone would miss.

   ✘  [CRITICAL] Line 6: DB_PASSWORD — weak or default value
   ⚠  [HIGH]     Line 5: AWS_ACCESS_KEY — cloud provider credential

   Summary: 1 CRITICAL  4 HIGH  1 MEDIUM

Enter fullscreen mode Exit fullscreen mode


✅ Pre-deploy validation

   razify validate .env .env.example

Enter fullscreen mode Exit fullscreen mode

Catches missing required variables before you deploy.
Returns exit code 1 — plugs straight into CI/CD.

   - name: Validate environment
     run: razify validate .env .env.example --json

Enter fullscreen mode Exit fullscreen mode


🛡️ Git commit protection

   razify guard install

Enter fullscreen mode Exit fullscreen mode

Installs a pre-commit hook that blocks any commit
containing exposed secrets. Set it once, forget about it.


📊 Health score

   razify audit .env .env.example

Enter fullscreen mode Exit fullscreen mode

Runs scan + validate + diff together.
Gives you a score out of 100 with actionable recommendations.


📄 Auto-generated docs

   razify docs .env.example -o ENV_DOCS.md

Enter fullscreen mode Exit fullscreen mode

Generates a markdown table from your inline comments.
No more "what does this variable do?"


Installation

   # macOS / Linux
   brew tap Hossiy21/tap && brew install razify

   # Windows
   scoop install razify

   # Go users
   go install github.com/Hossiy21/razify@latest

Enter fullscreen mode Exit fullscreen mode


Open source

MIT licensed. PRs very welcome — especially for new secret
patterns or improving the scoring algorithm.

⭐ github.com/Hossiy21/razify
🎬 Demo: https://github.com/Hossiy21/razify/raw/master/razify-demo.gif


Would love your feedback — especially on the entropy detection
and health scoring. What would make this useful for your workflow?