@ianwremmel @npmjs @heroku you can certainly hardcode your auth into .npmrc, but storing secrets in files is not a great security practice