from Hacker News

Postman is logging all your secrets and environment variables

by primitivesuave on 5/16/25, 2:02 PM with 9 comments

  • by az09mugen on 5/16/25, 5:50 PM

    I don't get why people still use postman when you have nice open-source tools such as Bruno [0], which actually can do a lot of what postman does, and more than that you can even import your postman collections.

    [0] : https://github.com/usebruno/bruno

  • by pjmlp on 5/16/25, 3:34 PM

    There is a reason why it is now a forbidden tool in many corporations.
  • by primitivesuave on 5/16/25, 2:02 PM

    I wrote up my findings on this late last night, so I would greatly appreciate anyone who might be able to give me an independent sanity check that this is actually what's happening.