惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
雷峰网
雷峰网
U
Unit 42
Y
Y Combinator Blog
I
InfoQ
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
量子位
Microsoft Security Blog
Microsoft Security Blog
B
Blog
The Cloudflare Blog
F
Fortinet All Blogs
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
C
Check Point Blog
S
SegmentFault 最新的问题
爱范儿
爱范儿
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
T
Tailwind CSS Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
I built a CLI that scans, validates and audits your .env ...
Hosaina Yirg · 2026-05-05 · via DEV Community

Hosaina Yirgalem

Every dev team has lost hours to .env problems.

A missing variable breaks a deploy.
An API key gets committed to Git.
A new teammate spends half a day figuring out which variables they need.
Nobody documented anything.

I built Razify to make all of that stop happening.


What is Razify?

Razify is a single binary CLI tool for .env file management.
It diffs, scans, validates, documents, and audits your environment
variables — all from your terminal.

  • No cloud account
  • No tracking
  • No Go installation required

Works with Node.js, Python, Ruby, Laravel, Rails — anything that uses .env files.


What it does

🔍 Secret scanning

   razify scan .env

Enter fullscreen mode Exit fullscreen mode

Detects leaked secrets using 80+ regex patterns combined with
Shannon entropy analysis to catch what pattern matching alone would miss.

   ✘  [CRITICAL] Line 6: DB_PASSWORD — weak or default value
   ⚠  [HIGH]     Line 5: AWS_ACCESS_KEY — cloud provider credential

   Summary: 1 CRITICAL  4 HIGH  1 MEDIUM

Enter fullscreen mode Exit fullscreen mode


✅ Pre-deploy validation

   razify validate .env .env.example

Enter fullscreen mode Exit fullscreen mode

Catches missing required variables before you deploy.
Returns exit code 1 — plugs straight into CI/CD.

   - name: Validate environment
     run: razify validate .env .env.example --json

Enter fullscreen mode Exit fullscreen mode


🛡️ Git commit protection

   razify guard install

Enter fullscreen mode Exit fullscreen mode

Installs a pre-commit hook that blocks any commit
containing exposed secrets. Set it once, forget about it.


📊 Health score

   razify audit .env .env.example

Enter fullscreen mode Exit fullscreen mode

Runs scan + validate + diff together.
Gives you a score out of 100 with actionable recommendations.


📄 Auto-generated docs

   razify docs .env.example -o ENV_DOCS.md

Enter fullscreen mode Exit fullscreen mode

Generates a markdown table from your inline comments.
No more "what does this variable do?"


Installation

   # macOS / Linux
   brew tap Hossiy21/tap && brew install razify

   # Windows
   scoop install razify

   # Go users
   go install github.com/Hossiy21/razify@latest

Enter fullscreen mode Exit fullscreen mode


Open source

MIT licensed. PRs very welcome — especially for new secret
patterns or improving the scoring algorithm.

⭐ github.com/Hossiy21/razify
🎬 Demo: https://github.com/Hossiy21/razify/raw/master/razify-demo.gif


Would love your feedback — especially on the entropy detection
and health scoring. What would make this useful for your workflow?