You can also set a `.pgpass` in your `$HOME` or point another path to a `PGPASSFILE` envar, so postgresql credentials don't leak to main org file.
https://www.postgresql.org/docs/current/libpq-pgpass.html