If a malcious pypi/npm/etc package could pop up on the build server any day, then all the secrets in environment variables are at risk.
https://threatpost.com/malicious-npm-packages-web-apps/178137/
Because these attacks aren't personal, you could break env var collectors with encryption even if the key was in plain sight. (yeah, if the payload is a full machine take over & your build server is being targeted personally, that's harder to fight)
♡ 0 ↻ 0