
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@byu-oit/dottfvars
Advanced tools
Loads environment variables from a .tfvars or .tfvars.json file into process.env
Parses a .tfvars or .tfvars.json file and adds the key value pairs
to the node environment variables (process.env). This module is
intended to be used in conjunction with the
env-var module.
Published on GPR and NPM.
npm i @byu-oit/dottfvars
Add contents of a tfvars file to process.env. The contents of process.env will not be overwritten by the contents of your tfvars.
import {resolve} from 'path'
import * as dottfvars from '@byu-oit/dottfvars'
import env from 'env-var'
dottfvars.from(resolve(__dirname, 'iac/development.tfvars'))
const imageId = env.from(process.env).get('image_id').asString()
Alternatively, you may define your tfvars as JSON and pass in a
.tfvars.json file path instead.
Sometimes you may just want the JSON representation of the tfvars file without merging it with process.env
import {resolve} from 'path'
import * as dottfvars from '@byu-oit/dottfvars'
import env from 'env-var'
const container = dottfvars.parse(resolve(__dirname, 'local.tfvars'))
const imageId = env.from(container).get('image_id').asString()
Related Packages:
FAQs
Loads environment variables from a .tfvars or .tfvars.json file into process.env
The npm package @byu-oit/dottfvars receives a total of 30 weekly downloads. As such, @byu-oit/dottfvars popularity was classified as not popular.
We found that @byu-oit/dottfvars demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 16 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.