Published a series of Node.js Secure Coding books

Do not use secrets in environment variables

An IDOR vulnerability was discovered in Clerk's Next.js SDK, what is it exactly?