"Stop using $thing", says company that happens to sell a replacement for $thing. Environment variables/files are certainly not perfect, but this is a very one-sided take on them.
I feel like with everything in computer science/software engineering, there are tradeoffs to every solution. What do you think are the positive benefits of .env files compared to what the author is saying?
Being able to roatate a secret in devenv & have things keep working is early intermediate maturity model, but I'd wager most orgs have nothing.
This isn't a dotenv problem, isn't a security problem. It's that no one has soaked time or your department stoggily refuses to try out the really good Ansible or whatnot env to set your various microservices up for local dev.