*Thanks so much to Bento for sponsoring this video and the channel this month. Check them out if you want an email service (and more) that just works. – https://bentonow.com/?via=joshcirre*
Something happened recently where a bunch of Laravel applictions were discovered to have public production APP_KEY's stored in their git repository. How could this happen? What should you do about it? How do you prevent it from happening? What even is an APP_KEY for Laravel and is it a secret?
Let's talk about it.
The Hacker News Article: https://thehackernews.com/2025/07/ove...
GitGuardian Article: https://blog.gitguardian.com/exploiti...
Rotating App Keys: https://laravel.com/docs/12.x/encrypt...
Encrypted Environment Variables: https://laravel.com/docs/12.x/configu...
---
🤔 *I'm still trying out Zed!:* • No More VSCode? My Thoughts After Using Ze...
📹 *Watch My VSCode Setup Video:* • My Minimal and Beautiful VSCode Setup
🎓 *Make VSCode Awesome – Caleb Porzio's Course (support me with this link):* https://gumroad.com/a/636621331
–
Timestamps:
00:00 What actually happened?
00:28 Thank you Bento
01:50 What are Laravel App Keys?
03:50 What happens when they get leaked?
08:29 Here's how to prevent it
16:24 Encrypted environment variables
19:00 You have to stay safe and smart