
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@vwinterdev/env-validator-vite
Advanced tools
Vite plugin for validating environment variables with built-in validators
Vite plugin for validating environment variables using a simple schema definition.
npm install @vwinterdev/env-validator-vite
# or
pnpm add @vwinterdev/env-validator-vite
# or
yarn add @vwinterdev/env-validator-vite
Note: This plugin uses lightweight built-in validators with zero external dependencies (except Vite).
// vite.config.ts
import { defineConfig } from 'vite'
import { envValidatorVite, SchemaVariant } from '@vwinterdev/env-validator-vite'
export default defineConfig({
plugins: [
envValidatorVite({
VITE_API_URL: SchemaVariant.URL,
VITE_API_KEY: SchemaVariant.STRING,
VITE_TIMEOUT: SchemaVariant.NUMBER,
VITE_DEBUG: SchemaVariant.BOOLEAN,
}),
],
})
import { defineConfig } from 'vite'
import { envValidatorVite, SchemaVariant } from '@vwinterdev/env-validator-vite'
export default defineConfig({
plugins: [
envValidatorVite({
// String validators
VITE_API_URL: SchemaVariant.URL,
VITE_EMAIL: SchemaVariant.EMAIL,
VITE_USER_ID: SchemaVariant.UUID,
VITE_SERVER_IP: SchemaVariant.IP,
VITE_API_KEY: SchemaVariant.STRING,
VITE_BUILD_TIME: SchemaVariant.DATETIME,
// Number validators
VITE_TIMEOUT: SchemaVariant.INTEGER,
VITE_PORT: SchemaVariant.POSITIVE_NUMBER,
// Other validators
VITE_DEBUG: SchemaVariant.BOOLEAN,
VITE_BUILD_DATE: SchemaVariant.DATE,
// Validators with parameters
VITE_ENV: {
schema: SchemaVariant.ENUM,
params: ['development', 'production', 'staging'],
},
VITE_PASSWORD: {
schema: SchemaVariant.MIN_LENGTH,
params: 8,
},
VITE_VERSION: {
schema: SchemaVariant.REGEX,
params: /^v\d+\.\d+\.\d+$/,
},
VITE_PORT: {
schema: SchemaVariant.MIN_NUMBER,
params: 1024,
},
}),
],
})
envValidatorVite(schema)SchemaVariant.STRING - Validates that the value is a stringSchemaVariant.URL - Validates that the value is a valid URLSchemaVariant.EMAIL - Validates that the value is a valid email addressSchemaVariant.UUID - Validates that the value is a valid UUIDSchemaVariant.IP - Validates that the value is a valid IP address (IPv4 or IPv6)SchemaVariant.DATETIME - Validates that the value is a valid ISO 8601 datetime stringSchemaVariant.MIN_LENGTH - Validates minimum string length
{ schema: SchemaVariant.MIN_LENGTH, params: 8 }
SchemaVariant.MAX_LENGTH - Validates maximum string length
{ schema: SchemaVariant.MAX_LENGTH, params: 100 }
SchemaVariant.LENGTH - Validates exact string length
{ schema: SchemaVariant.LENGTH, params: 16 }
SchemaVariant.REGEX - Validates against a regular expression
{ schema: SchemaVariant.REGEX, params: /^[A-Z]+$/ }
// or
{ schema: SchemaVariant.REGEX, params: '^[A-Z]+$' }
SchemaVariant.NUMBER - Validates and coerces the value to a numberSchemaVariant.INTEGER - Validates and coerces to an integerSchemaVariant.POSITIVE_NUMBER - Validates a positive numberSchemaVariant.NEGATIVE_NUMBER - Validates a negative numberSchemaVariant.MIN_NUMBER - Validates minimum number value
{ schema: SchemaVariant.MIN_NUMBER, params: 0 }
SchemaVariant.MAX_NUMBER - Validates maximum number value
{ schema: SchemaVariant.MAX_NUMBER, params: 65535 }
SchemaVariant.BOOLEAN - Validates and coerces the value to a booleanSchemaVariant.DATE - Validates and coerces to a Date objectSchemaVariant.ENUM - Validates that the value is one of the provided options
{ schema: SchemaVariant.ENUM, params: ['option1', 'option2'] }
The plugin validates all environment variables that start with VITE_ prefix (which is the standard for Vite). The validation happens during the configResolved hook, before the build process continues.
If validation fails, the plugin will:
MIT
FAQs
Vite plugin for validating environment variables with built-in validators
We found that @vwinterdev/env-validator-vite demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.