Theo Ephraim @theozero.bsky.social · 25/08/2026🎁 for the @nuxt.com devs - new varlock+nuxt integration just dropped. Supports log redaction, leak prevention, control over which vars get bundled. And of course validation, type safety, load secrets via plugins, imports... Would love to hear what you think! npmx.dev/package/@var...npmx.dev@varlock/nuxt-integration - npmxNuxt module to use varlock for .env file loading - adds validation, type-safety, and extra security features 1173
Reposted by Theo EphraimAdam @u11g.com · 15/08/2026AI-safe env files with minimal workflow change is a narrow tool with immediate payoff. varlock.devvarlock.devVarlock - AI-safe .env filesAI-safe .env files: schemas for agents, secrets for humans. Validate, secure, and share environment variables with type-safety, leak prevention, and integrations for Next.js, Vite, Astro, and more. 1271
Theo Ephraim @theozero.bsky.social · 21/07/2026Varlock now includes "credential brokering" functionality - your agent (or whatever process) gets only _placeholder_ credentials, and real secrets are swapped in over the wire (MITM proxy). Rules are configured in your existing .env.schema Would love to hear your feedback! 191
Reposted by Theo EphraimSal Rahman @manlycoffee.techhub.social.ap.brid.gy · 21/07/2026I was previously tending a booth for a product called Varlock. They're incredibly useful for credentials management. Definitely worth a look. They brand themselves as "credentials management in the AI era". github.com/dmno-dev/varlockgithub.comGitHub - dmno-dev/varlock: AI-safe .env files: Schemas for agents, Secrets for humans.AI-safe .env files: Schemas for agents, Secrets for humans. - dmno-dev/varlock 062
Theo Ephraim @theozero.bsky.social · 15/07/2026Random q - do folks out there care / think about how much plastic they are exposed to? Talking things like coffee gear, water bottles / mugs, cookware, baby products. Do you research before you buy? Would you like to minimize but takes too much work? Never think about it? I'm cooking something :) 030
Theo Ephraim @theozero.bsky.social · 15/07/2026Building a new CLI tool? Here is your toolkit: - gunshi (cli framework) - clack/prompts (cli prompts) - lefthook (git hooks) - tsdown (ts build tool) - bumpy (changelog + publishing) - fledgling (bonus) - for initial npm claim and oidc setup 0160
Theo Ephraim @theozero.bsky.social · 11/07/2026Citing the recent bun drama, David Bowie will be re-releasing old albums as "Rusty Stardust" 020
Theo Ephraim @theozero.bsky.social · 10/07/2026Super fun chatting with @brandonwhichard.com about varlock. He is a real user - found us through a listener and has been using it ever since. Have a listen! 🎧 031
Theo Ephraim @theozero.bsky.social · 09/07/2026All varlock docs package links and readmes (as of their next publish) now point to @npmx.dev ♥️🧙♂️ 1161
Theo Ephraim @theozero.bsky.social · 07/07/2026PSA - @astro.build + yaml w/ md + @cloudflare.social + LLMs is a killer toolkit to build comprehensive resources of info gathered from all over the web. No servers, no DB, no tedious hand-maintaining data. Ideas that would take way too much effort before are now easily within reach. 010
Theo Ephraim @theozero.bsky.social · 07/07/2026🧙♂️ varlock@1.10 adds arbitrary codegen. As well as built-in support for php, python, go, rust - so you get a fully typed+coerced env loader to use in your code. Plugins can add codegen types - new possibilities to generate for k8s, terraform... anything! varlock.dev/guides/code-...varlock.devCode generationGenerate types and other code from your env schema, and extend it with plugins 161
Theo Ephraim @theozero.bsky.social · 06/07/2026Finally digging into a proper plugin system for bumpy 🐸 (bumpy.varlock.dev). This means native support / recipes to release to common js targets like jsr, vscode marketplace, and non-js things like PyPi, and crates.iobumpy.varlock.devGitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy 160
Theo Ephraim @theozero.bsky.social · 05/07/2026btw - I added condiments to my food storage tips site 🫙🍓howtostore.foodMustard storage guide | HowToStore.foodMustard is shelf-stable thanks to its vinegar and salt, so the pantry is perfectly safe before and after opening. Refrigerating an open jar keeps it spi... 1100
Theo Ephraim @theozero.bsky.social · 04/07/2026varlock will soon support arbitrary codegen registered in plugins. Opens up fun possibilities - generate zod schema, k8s configmap/secret split based on what's marked @sensitive, terraform vars Plus new built-in env generation for rust, go, python, php. Excited to see how you will use it! 🧙♂️✨ 0190
Theo Ephraim @theozero.bsky.social · 02/07/2026varlock credential broker is coming very soon! child process (usually AI agent) gets _placeholders_, swapped for real creds at the network boundary. Rules managed from your .env.schema - use our existing plugins to pull from anywhere. Can't wait to share it :) 030
Theo Ephraim @theozero.bsky.social · 30/06/2026Hey @pnpm.io - following up on our recent thread about using valid env vars for configuring npmrc auth -- github.com/orgs/pnpm/di...github.comUsing valid env vars names for .npmrc · pnpm · Discussion #12746First off, thanks for the env-variables-in-repository-npmrc post and for closing the ${ENV}-in-repo-file exfiltration hole. Locking expansion to trusted sources is the right call. This is a follow-... 020
Theo Ephraim @theozero.bsky.social · 29/06/2026npm staged publishing approval tool MVP is working. Batch approve multiple packages, multi-sig approval policies, audit trails, batches created in CI via OIDC. NPM token encrypted by passkeys so we never see them. Using staged publishing? Wanting to but avoiding because its clunky? Let me know! 100
Theo Ephraim @theozero.bsky.social · 26/06/2026My new npm staged publishing approval tool is called "stageflight" - HMU if you want to beta test! Provides batch approvals, multi-sig policies w/ audit trails, approvers don't need publishing rights. Cloud-hosted but secrets encrypted w/ your passkeys. optional ai review too in future 010
Theo Ephraim @theozero.bsky.social · 26/06/2026Working on something pretty rad that’s going to help make npm staged publishing feel much nicer - and even more secure. Like/comment/DM if this is up your alley and you want to help me beta test. 110
Theo Ephraim @theozero.bsky.social · 23/06/2026🐸 bumpy.varlock.dev continues to get better and more solid. If you release npm packages - take it for a spin and let me know what you think! Couples very nicely with 🐣 fledgling.varlock.dev especially in a monorepo :)bumpy.varlock.devGitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy 141
Theo Ephraim @theozero.bsky.social · 23/06/2026Doesn't exactly inspire confidence when things show an error message even when they work. A few npm interactions regularly do this for me - approving staged publishing being one of them. 210
Theo Ephraim @theozero.bsky.social · 18/06/2026Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling` 2177
Theo Ephraim @theozero.bsky.social · 18/06/2026🥚🐣🐥 Hatching something fun tomorrow. A very nice complement to bumpy 🐸 010
Theo Ephraim @theozero.bsky.social · 17/06/2026New varlock+mise guide varlock.dev/integrations... Would appreciate a look from any heavy mise users!varlock.devmiseInstall varlock with mise and wire validated env vars into your tasks 062
Theo Ephraim @theozero.bsky.social · 16/06/2026How many of y'all use @1password.bsky.social wired into dev/agent workflows? varlock now has built-in caching (secured by secure enclave), meaning fewer roundtrips to 1pass servers. Much smoother for when things are reloading a lot. varlock.dev/plugins/1pas... varlock.dev/guides/cachi...varlock.dev1Password PluginUsing 1Password with Varlock 120
Theo Ephraim @theozero.bsky.social · 13/06/2026Honestly didn't know what to expect when I started on prerelease channels for 🐸 bumpy (publish v1.2.3-rc.1 and tag as "next") I knew it's awkward and hard to deal with - one of most complained about parts of changesets 🦋 But the end result is actually really good! github.com/dmno-dev/bum...github.com 000
Theo Ephraim @theozero.bsky.social · 12/06/2026pre-release channels are looking good on bumpy 🐸 Same workflow, just merge to _next_. Then merge _next_ to _main_. Anyone out there using a npm preview release channel and not quite happy with their current setup? Hit me up! bumpy.varlock.dev 032
Theo Ephraim @theozero.bsky.social · 10/06/2026Looking at adding long-lived pre-release channels to bumpy.varlock.dev (one most confusing/complained about parts of changesets 🦋) not implemented yet, but here is the plan -- github.com/dmno-dev/bum... If anyone has thought about this deeply and has any feedback I'd be very grateful!bumpy.varlock.devGitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy 000
Reposted by Theo Ephraimhenry ✷ @strange.website · 05/05/2025when starting a new project repo, choosing a tech stack, etc, i try to always ask the hard and important questions right up front, such as: “how do i work this?”, “what is that beautiful house?”, “where does that highway go to?”, “am I right? am I wrong?”, and “my god! what have I done?” 2389
Theo Ephraim @theozero.bsky.social · 04/06/2026set up bumpy.varlock.dev in your repo and I'll send you a sweet bumpy sticker 🐸 260
Theo Ephraim @theozero.bsky.social · 02/06/2026Updated bumpy.varlock.dev recommended release workflow. OIDC token is now injected only during publish, not during create/update version PR, also locked down to a github environment with branch protections. Everyone go turn on staged publishing now! And use bumpy :) 🏗️🐸🔐bumpy.varlock.devGitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy 000
Theo Ephraim @theozero.bsky.social · 02/06/2026Any really great examples of css view transitions? I built howtostore.food as a fun side project and went pretty deep on it. Haven't really seen anything like it.howtostore.foodFood Storage Guide | HowToStore.foodHow to store food so it stays fresh longer. Storage guides by item, method, and category. 011
Reposted by Theo EphraimDarcy Clarke @darcyclarke.me · 01/06/2026⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours. 22417
Theo Ephraim @theozero.bsky.social · 01/06/2026If you are using varlock, try `npx skills add dmno-dev/varlock` to install our new varlock skill. I wish the DX around this was better to keep skills published along with npm modules in sync, but this seemed like the best solution for now. 010
Theo Ephraim @theozero.bsky.social · 01/06/2026think varlock is neat? Please go “like” it on npmx npmx.dev/package/varl... Bumpy too :) npmx.dev/package/@var...npmx.devvarlock - npmxAI-safe .env files: Schemas for agents, Secrets for humans. 020
Theo Ephraim @theozero.bsky.social · 30/05/2026Putting together a bsky list of folks who build/maintain release tooling (e.g., changesets, release-it, uppt, bumpy, etc). What tools / people am I missing bsky.app/profile/did:... 8152
Theo Ephraim @theozero.bsky.social · 29/05/2026bumpy.varlock.dev now adds section to GH release showing targets w/ status+links. Uses hidden metadata, release updated until finalized. Next step is adding plugins so you can release to multiple places (npm, jsr, vscode extension marketplace, etc) cc @nullvoxpopuli.com 120
Theo Ephraim @theozero.bsky.social · 28/05/2026What is current best practice on how to include/publish skills with npm packages? Seems like the wild west out there... 100
Reposted by Theo Ephraimnaugtur @naugtur.pl · 28/05/2026📦 Set up staged publishing with approximately 1 click per package lavamoat.github.io/stageclicker/ Without sharing any of your permissions or exposing access to anything.lavamoat.github.ioDrag this button to your bookmarks bar to save it as a bookmarklet: 2117
Theo Ephraim @theozero.bsky.social · 26/05/2026While on the topic of NPM, the varlock package now has ~125k weekly downloads, but is still not indexed by google. Some of our other packages have minimal usage are a indexed properly. Any idea what is going on...? Anyone else have this experience?npmjs.com 000
Theo Ephraim @theozero.bsky.social · 26/05/2026I'd love to build some better workflows around staged publishing approval, rather than rely on npm's UI and 2fa. Looking to get this feedback to the right folks github.com/orgs/communi... /cc npm release tool authors @danielroe.dev @notwes.bsky.social @nullvoxpopuli.com @jovidecroock.comgithub.comstaged approval customization · community · Discussion #196948🏷️ Discussion Type Product Feedback Body Thanks for getting out staged publishing. Adding that final check isolated from CI is an important step. I'd like to implement my own staged approval workfl... 4124
Theo Ephraim @theozero.bsky.social · 26/05/2026🐸 bumpy.varlock.dev now supports npm staged publishing for complex monorepos 🎉 - create bump file(s) in PR w/ bump level (patch/minor/major) and changelog content - PR merges, a "release PR" is created/updated - release PR merges, new package(s) staged - approve on npm w/ 2fa to releasebumpy.varlock.devGitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy 190
Theo Ephraim @theozero.bsky.social · 20/05/2026Should we just fund the company by selling merch? 🧙♂️🤘 160
Reposted by Theo Ephraimdaniel wraith @danielroe.dev · 20/05/2026this is a fantastic thread full of very useful advice + some golden tools 🏆 1299
Theo Ephraim @theozero.bsky.social · 06/05/2026As of today @varlock.dev has OIDC workload identity support - this means that for some popular combos of deployment platform + secret storage, you no longer need a secret-zero to pull the rest of your sensitive data. check out varlock.dev/guides/oidc/ to get startedvarlock.devOIDC Workload IdentityAuthenticate with secret providers using OIDC tokens from your deployment platform — no long-lived credentials needed 081
Theo Ephraim @theozero.bsky.social · 30/04/2026Varlock v1 also now has built-in macOS keychain support. Write `ITEM=keychain(prompt)` and you get a native mac popup to choose/add an item. It writes back to your schema with the id. ACL is limited and reading is gated behind fingerprint. 150