It was discussed in https://news.ycombinator.com/item?id=45670052 and others chimed in with their own (like bkt(1) and up(1)).
The main differences I see:
- memo doesn't need to be built (its a shell script)
- once keeps output cache in a running daemon. By contrast, memo stores content under /tmp with whatever the best compression available is (it prefers zstd). There's trade-offs in that. More pareto-optimal from the security front may be to have a sort of session key and to compress-then-encrypt files on disk.Been using this, for similar cli output catching. https://github.com/dimo414/bkt
Wondering what you think about the two, and what are the good reasons to use one vs the other? (Maybe: once is more actively developed? bkt hasn't been active for a year).
Nixos does this for builds, but I've not seen it generalized to arbitrary processes.
$ cmake ..
$ output | grep "libssl version"Uh I dont know about that one chief.
It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.
I'll take security by inconvenience over building what becomes the primary reason for a security incident.
If you have allowed an agent to access any kind of credential, you should assume it is no longer private.
For example, I have a script for automating the creation of PRs which fetches the available labels for a repo from github and presents them with fzf multi select. I store the labels with a TTL of a week so that I don’t have to fetch them every time and the script compares the file’s age against the desired TTL to invalidate.
I find it useful for augmenting other programs, but I’m not typically using it on the cli directly.
Not sure if there could be other interesting uses. I can’t think of one anyways.
I just want to avoid leaving my credentials and secrets on the filesystem.
EDIT: I use a lot of direnv / mise. So reloading credentials with different values is common.