From 7c1912d5c0acf9d0656eeee59193636431c0d2cf Mon Sep 17 00:00:00 2001 From: "EVA (Entity Value Attribute)" Date: Thu, 11 Jun 2026 12:44:23 +0300 Subject: [PATCH] Added recommendation to avoid preserving secret in the shell history --- README.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index c7d9f099..e1a761de 100644 --- a/README.md +++ b/README.md @@ -95,7 +95,11 @@ This means you don’t need: Store the secret in your OS keychain: ```bash -docker pass set foo=bar +# reads the secret from stdin, to avoid exposure in cmdline (e.g. in htop) and shell history (recommended) +docker pass set foo + +# passing directly supported as well +docker pass set foo=secret ``` Run a container using a secret reference (the value se://foo is not the secret itself):