A year ago I'd have told you a .env file was fine.
Then we patched a CVSS 10.0 RCE in Next.js CVE-2025-66478https://nextjs.org/blog/CVE-2025-66478 and spent the next two days rotating every secret we owned — because we couldn't prove which ones an a...