Postman is logging all your secrets and environment variables

20 primitivesuave 5 5/16/2025, 2:02:00 PM anonymousdata.medium.com ↗

Comments (5)

az09mugen · 3h ago
I don't get why people still use postman when you have nice open-source tools such as Bruno [0], which actually can do a lot of what postman does, and more than that you can even import your postman collections.

[0] : https://github.com/usebruno/bruno

primitivesuave · 3h ago
Thank you so much for sharing this. We're actively looking for alternatives to Postman right now, and would be heavily inclined toward an OSS solution.
az09mugen · 2h ago
You're welcome, and thanks a lot for sharing this article.
pjmlp · 6h ago
There is a reason why it is now a forbidden tool in many corporations.
primitivesuave · 7h ago
I wrote up my findings on this late last night, so I would greatly appreciate anyone who might be able to give me an independent sanity check that this is actually what's happening.