Sign in

Theo Ephraim

@theozero.bsky.social
181 followers 126 following 230 posts

🧙‍♂️🪄🔒 varlock.dev Open sourcerer, devtools builder, entrepreneur

PostsRepliesMedia
Theo Ephraim @theozero.bsky.social · 21/09/2026
🧙‍♂️🔐 casting viral growth spell
000
Theo Ephraim @theozero.bsky.social · 16/09/2026
varlock knip plugin! ♥️
140
Theo Ephraim @theozero.bsky.social · 25/08/2026
🎁 for the @nuxt.com devs - new varlock+nuxt integration just dropped. Supports log redaction, leak prevention, control over which vars get bundled. And of course validation, type safety, load secrets via plugins, imports... Would love to hear what you think! npmx.dev/package/@var...
npmx.dev
@varlock/nuxt-integration - npmx
Nuxt module to use varlock for .env file loading - adds validation, type-safety, and extra security features
1173
Reposted by Theo Ephraim
Adam @u11g.com · 15/08/2026
AI-safe env files with minimal workflow change is a narrow tool with immediate payoff. varlock.dev
varlock.dev
Varlock - AI-safe .env files
AI-safe .env files: schemas for agents, secrets for humans. Validate, secure, and share environment variables with type-safety, leak prevention, and integrations for Next.js, Vite, Astro, and more.
1271
Theo Ephraim @theozero.bsky.social · 21/07/2026
Varlock now includes "credential brokering" functionality - your agent (or whatever process) gets only _placeholder_ credentials, and real secrets are swapped in over the wire (MITM proxy). Rules are configured in your existing .env.schema Would love to hear your feedback!
191
Reposted by Theo Ephraim
Sal Rahman @manlycoffee.techhub.social.ap.brid.gy · 21/07/2026
I was previously tending a booth for a product called Varlock. They're incredibly useful for credentials management. Definitely worth a look. They brand themselves as "credentials management in the AI era". github.com/dmno-dev/varlock
github.com
GitHub - dmno-dev/varlock: AI-safe .env files: Schemas for agents, Secrets for humans.
AI-safe .env files: Schemas for agents, Secrets for humans. - dmno-dev/varlock
062
Theo Ephraim @theozero.bsky.social · 15/07/2026
Random q - do folks out there care / think about how much plastic they are exposed to? Talking things like coffee gear, water bottles / mugs, cookware, baby products. Do you research before you buy? Would you like to minimize but takes too much work? Never think about it? I'm cooking something :)
030
Theo Ephraim @theozero.bsky.social · 15/07/2026
Building a new CLI tool? Here is your toolkit: - gunshi (cli framework) - clack/prompts (cli prompts) - lefthook (git hooks) - tsdown (ts build tool) - bumpy (changelog + publishing) - fledgling (bonus) - for initial npm claim and oidc setup
0160
Theo Ephraim @theozero.bsky.social · 11/07/2026
Citing the recent bun drama, David Bowie will be re-releasing old albums as "Rusty Stardust"
020
Theo Ephraim @theozero.bsky.social · 10/07/2026
Super fun chatting with @brandonwhichard.com about varlock. He is a real user - found us through a listener and has been using it ever since. Have a listen! 🎧
031
Theo Ephraim @theozero.bsky.social · 09/07/2026
All varlock docs package links and readmes (as of their next publish) now point to @npmx.dev ♥️🧙‍♂️
1161
Theo Ephraim @theozero.bsky.social · 07/07/2026
PSA - @astro.build + yaml w/ md + @cloudflare.social + LLMs is a killer toolkit to build comprehensive resources of info gathered from all over the web. No servers, no DB, no tedious hand-maintaining data. Ideas that would take way too much effort before are now easily within reach.
010
Theo Ephraim @theozero.bsky.social · 07/07/2026
🧙‍♂️ varlock@1.10 adds arbitrary codegen. As well as built-in support for php, python, go, rust - so you get a fully typed+coerced env loader to use in your code. Plugins can add codegen types - new possibilities to generate for k8s, terraform... anything! varlock.dev/guides/code-...
varlock.dev
Code generation
Generate types and other code from your env schema, and extend it with plugins
161
Theo Ephraim @theozero.bsky.social · 06/07/2026
Finally digging into a proper plugin system for bumpy 🐸 (bumpy.varlock.dev). This means native support / recipes to release to common js targets like jsr, vscode marketplace, and non-js things like PyPi, and crates.io
bumpy.varlock.dev
GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool
🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy
160
Theo Ephraim @theozero.bsky.social · 05/07/2026
btw - I added condiments to my food storage tips site 🫙🍓
howtostore.food
Mustard storage guide | HowToStore.food
Mustard is shelf-stable thanks to its vinegar and salt, so the pantry is perfectly safe before and after opening. Refrigerating an open jar keeps it spi...
1100
Theo Ephraim @theozero.bsky.social · 04/07/2026
varlock will soon support arbitrary codegen registered in plugins. Opens up fun possibilities - generate zod schema, k8s configmap/secret split based on what's marked @sensitive, terraform vars Plus new built-in env generation for rust, go, python, php. Excited to see how you will use it! 🧙‍♂️✨
0190
Theo Ephraim @theozero.bsky.social · 02/07/2026
varlock credential broker is coming very soon! child process (usually AI agent) gets _placeholders_, swapped for real creds at the network boundary. Rules managed from your .env.schema - use our existing plugins to pull from anywhere. Can't wait to share it :)
030
Theo Ephraim @theozero.bsky.social · 30/06/2026
Hey @pnpm.io - following up on our recent thread about using valid env vars for configuring npmrc auth -- github.com/orgs/pnpm/di...
github.com
Using valid env vars names for .npmrc · pnpm · Discussion #12746
First off, thanks for the env-variables-in-repository-npmrc post and for closing the ${ENV}-in-repo-file exfiltration hole. Locking expansion to trusted sources is the right call. This is a follow-...
020
Theo Ephraim @theozero.bsky.social · 29/06/2026
npm staged publishing approval tool MVP is working. Batch approve multiple packages, multi-sig approval policies, audit trails, batches created in CI via OIDC. NPM token encrypted by passkeys so we never see them. Using staged publishing? Wanting to but avoiding because its clunky? Let me know!
100
Theo Ephraim @theozero.bsky.social · 26/06/2026
My new npm staged publishing approval tool is called "stageflight" - HMU if you want to beta test! Provides batch approvals, multi-sig policies w/ audit trails, approvers don't need publishing rights. Cloud-hosted but secrets encrypted w/ your passkeys. optional ai review too in future
010
Theo Ephraim @theozero.bsky.social · 26/06/2026
Working on something pretty rad that’s going to help make npm staged publishing feel much nicer - and even more secure. Like/comment/DM if this is up your alley and you want to help me beta test.
110
Theo Ephraim @theozero.bsky.social · 23/06/2026
🐸 bumpy.varlock.dev continues to get better and more solid. If you release npm packages - take it for a spin and let me know what you think! Couples very nicely with 🐣 fledgling.varlock.dev especially in a monorepo :)
bumpy.varlock.dev
GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool
🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy
141
Theo Ephraim @theozero.bsky.social · 23/06/2026
Doesn't exactly inspire confidence when things show an error message even when they work. A few npm interactions regularly do this for me - approving staged publishing being one of them.
210
Theo Ephraim @theozero.bsky.social · 18/06/2026
Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling`
2177
Theo Ephraim @theozero.bsky.social · 18/06/2026
🥚🐣🐥 Hatching something fun tomorrow. A very nice complement to bumpy 🐸
010
Theo Ephraim @theozero.bsky.social · 17/06/2026
New varlock+mise guide varlock.dev/integrations... Would appreciate a look from any heavy mise users!
varlock.dev
mise
Install varlock with mise and wire validated env vars into your tasks
062
Theo Ephraim @theozero.bsky.social · 16/06/2026
How many of y'all use @1password.bsky.social wired into dev/agent workflows? varlock now has built-in caching (secured by secure enclave), meaning fewer roundtrips to 1pass servers. Much smoother for when things are reloading a lot. varlock.dev/plugins/1pas... varlock.dev/guides/cachi...
varlock.dev
1Password Plugin
Using 1Password with Varlock
120
Theo Ephraim @theozero.bsky.social · 13/06/2026
Honestly didn't know what to expect when I started on prerelease channels for 🐸 bumpy (publish v1.2.3-rc.1 and tag as "next") I knew it's awkward and hard to deal with - one of most complained about parts of changesets 🦋 But the end result is actually really good! github.com/dmno-dev/bum...
github.com
000
Theo Ephraim @theozero.bsky.social · 12/06/2026
pre-release channels are looking good on bumpy 🐸 Same workflow, just merge to _next_. Then merge _next_ to _main_. Anyone out there using a npm preview release channel and not quite happy with their current setup? Hit me up! bumpy.varlock.dev
032
Theo Ephraim @theozero.bsky.social · 10/06/2026
Looking at adding long-lived pre-release channels to bumpy.varlock.dev (one most confusing/complained about parts of changesets 🦋) not implemented yet, but here is the plan -- github.com/dmno-dev/bum... If anyone has thought about this deeply and has any feedback I'd be very grateful!
bumpy.varlock.dev
GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool
🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy
000
Reposted by Theo Ephraim
Nick Rempel @nrempel.com · 06/06/2026
15992247
Reposted by Theo Ephraim
henry ✷ @strange.website · 05/05/2025
when starting a new project repo, choosing a tech stack, etc, i try to always ask the hard and important questions right up front, such as: “how do i work this?”, “what is that beautiful house?”, “where does that highway go to?”, “am I right? am I wrong?”, and “my god! what have I done?”
2389
Theo Ephraim @theozero.bsky.social · 04/06/2026
set up bumpy.varlock.dev in your repo and I'll send you a sweet bumpy sticker 🐸
260
Theo Ephraim @theozero.bsky.social · 03/06/2026
that's what I like to see 🧙‍♂️✨🔐
050
Theo Ephraim @theozero.bsky.social · 02/06/2026
Updated bumpy.varlock.dev recommended release workflow. OIDC token is now injected only during publish, not during create/update version PR, also locked down to a github environment with branch protections. Everyone go turn on staged publishing now! And use bumpy :) 🏗️🐸🔐
bumpy.varlock.dev
GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool
🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy
000
Theo Ephraim @theozero.bsky.social · 02/06/2026
Any really great examples of css view transitions? I built howtostore.food as a fun side project and went pretty deep on it. Haven't really seen anything like it.
howtostore.food
Food Storage Guide | HowToStore.food
How to store food so it stays fresh longer. Storage guides by item, method, and category.
011
Reposted by Theo Ephraim
Darcy Clarke @darcyclarke.me · 01/06/2026
⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours.
22417
Theo Ephraim @theozero.bsky.social · 01/06/2026
If you are using varlock, try `npx skills add dmno-dev/varlock` to install our new varlock skill. I wish the DX around this was better to keep skills published along with npm modules in sync, but this seemed like the best solution for now.
010
Theo Ephraim @theozero.bsky.social · 01/06/2026
think varlock is neat? Please go “like” it on npmx npmx.dev/package/varl... Bumpy too :) npmx.dev/package/@var...
npmx.dev
varlock - npmx
AI-safe .env files: Schemas for agents, Secrets for humans.
020
Theo Ephraim @theozero.bsky.social · 30/05/2026
Putting together a bsky list of folks who build/maintain release tooling (e.g., changesets, release-it, uppt, bumpy, etc). What tools / people am I missing bsky.app/profile/did:...
8152
Theo Ephraim @theozero.bsky.social · 29/05/2026
bumpy.varlock.dev now adds section to GH release showing targets w/ status+links. Uses hidden metadata, release updated until finalized. Next step is adding plugins so you can release to multiple places (npm, jsr, vscode extension marketplace, etc) cc @nullvoxpopuli.com
120
Theo Ephraim @theozero.bsky.social · 28/05/2026
What is current best practice on how to include/publish skills with npm packages? Seems like the wild west out there...
100
Reposted by Theo Ephraim
naugtur @naugtur.pl · 28/05/2026
📦 Set up staged publishing with approximately 1 click per package lavamoat.github.io/stageclicker/ Without sharing any of your permissions or exposing access to anything.
lavamoat.github.io
Drag this button to your bookmarks bar to save it as a bookmarklet:
2117
Theo Ephraim @theozero.bsky.social · 26/05/2026
While on the topic of NPM, the varlock package now has ~125k weekly downloads, but is still not indexed by google. Some of our other packages have minimal usage are a indexed properly. Any idea what is going on...? Anyone else have this experience?
npmjs.com
000
Theo Ephraim @theozero.bsky.social · 26/05/2026
I'd love to build some better workflows around staged publishing approval, rather than rely on npm's UI and 2fa. Looking to get this feedback to the right folks github.com/orgs/communi... /cc npm release tool authors @danielroe.dev @notwes.bsky.social @nullvoxpopuli.com @jovidecroock.com
github.com
staged approval customization · community · Discussion #196948
🏷️ Discussion Type Product Feedback Body Thanks for getting out staged publishing. Adding that final check isolated from CI is an important step. I'd like to implement my own staged approval workfl...
4124
Theo Ephraim @theozero.bsky.social · 26/05/2026
🐸 bumpy.varlock.dev now supports npm staged publishing for complex monorepos 🎉 - create bump file(s) in PR w/ bump level (patch/minor/major) and changelog content - PR merges, a "release PR" is created/updated - release PR merges, new package(s) staged - approve on npm w/ 2fa to release
bumpy.varlock.dev
GitHub - dmno-dev/bumpy: 🐸 Modern monorepo friendly version management + changelog tool
🐸 Modern monorepo friendly version management + changelog tool - dmno-dev/bumpy
190
Theo Ephraim @theozero.bsky.social · 20/05/2026
Should we just fund the company by selling merch? 🧙‍♂️🤘
160
Reposted by Theo Ephraim
daniel wraith @danielroe.dev · 20/05/2026
this is a fantastic thread full of very useful advice + some golden tools 🏆
1299
Theo Ephraim @theozero.bsky.social · 06/05/2026
As of today @varlock.dev has OIDC workload identity support - this means that for some popular combos of deployment platform + secret storage, you no longer need a secret-zero to pull the rest of your sensitive data. check out varlock.dev/guides/oidc/ to get started
varlock.dev
OIDC Workload Identity
Authenticate with secret providers using OIDC tokens from your deployment platform — no long-lived credentials needed
081
Theo Ephraim @theozero.bsky.social · 30/04/2026
Varlock v1 also now has built-in macOS keychain support. Write `ITEM=keychain(prompt)` and you get a native mac popup to choose/add an item. It writes back to your schema with the id. ACL is limited and reading is gated behind fingerprint.
native mac popup letting you add a new item to macOS keychain, which will then be loaded by varlock. This is triggered by `KEYCHAIN_ITEM=keychain(prompt)` in a .env.local file
150