
Security News
TC39 Advances 11 Proposals for Math Precision, Binary APIs, and More
TC39 advances 11 JavaScript proposals, with two moving to Stage 4, bringing better math, binary APIs, and more features one step closer to the ECMAScript spec.
dotenv-safe
Advanced tools
Identical to dotenv
, but ensures that all needed environment variables are defined after reading from .env
.
The names of the needed variables are read from .env.example
, which should be commited along with your project.
dotenv-safe
only checks if all the needed variable names exist in process.env
after initialising. It does not assume anything about the presence, format or validity of the values.
npm install dotenv-safe
pnpm install dotenv-safe
yarn add dotenv-safe
# .env.example, committed to repo
SECRET=
TOKEN=
KEY=
# .env, private
SECRET=topsecret
TOKEN=
// index.js
require('dotenv-safe').config();
Or, if you are using ES modules:
// index.mjs
import { config } from 'dotenv-safe';
config();
Since the provided .env
file does not contain all the variables defined in
.env.example
, an exception is thrown:
MissingEnvVarsError: The following variables were defined in .env.example but are not present in the environment:
TOKEN, KEY
Make sure to add them to .env or directly to the environment.
If you expect any of these variables to be empty, you can use the allowEmptyValues option:
require('dotenv-safe').config({
allowEmptyValues: true
});
Not all the variables have to be defined in .env
; they can be supplied externally.
For example, the following would work:
$ TOKEN=abc KEY=xyz node index.js
Requiring and loading is identical:
require('dotenv-safe').config();
This will load environment variables from .env
as usual, but will also read any variables defined in .env.example
.
If any variables are already defined in the environment before reading from .env
, they will not be overwritten.
If any variables are missing from the environment, a MissingEnvVarsError
will be thrown, which lists the missing variables.
Otherwise, returns an object with the following format:
{
parsed: { SECRET: 'topsecret', TOKEN: '' }, // parsed representation of .env
required: { SECRET: 'topsecret', TOKEN: 'external' } /* key-value pairs required by .env.example
and defined by environment */
}
If all the required variables were successfully read but an error was thrown when trying to read the .env
file, the error will be included in the result object under the error
key.
dotenv-safe
compares the actual environment after loading .env
(if any) with the example file, so it will work correctly if environment variables are missing in .env
but provided through other means such as a shell script.
You can use the --require
(-r
) command line option to preload dotenv-safe.
By doing this, you do not need to require and load dotenv in your application code.
This is the preferred approach when using import instead of require.
$ node -r dotenv-safe/config your_script.js
See the dotenv README for more information.
It can be useful to depend on a different set of example variables when running in a CI environment.
This can be done by checking if the CI
environment variable is defined, which is supported by virtually all CI solutions.
For example:
require('dotenv-safe').config({
example: process.env.CI ? '.env.ci.example' : '.env.example'
});
Same options and methods supported by dotenv
, in addition to the options below:
require('dotenv-safe').config({
allowEmptyValues: true,
example: './.my-env-example-filename'
});
Starting from version 9.0.0, dotenv
is a peer dependency of dotenv-safe
. This means that the actual version of dotenv
used defaults to the latest available at install time, or whatever is specified by your application.
allowEmptyValues
If a variable is defined in the example file and has an empty value in the environment, enabling this option will not throw an error after loading.
Defaults to false
.
example
Path to example environment file.
Defaults to .env.example
.
I regularly use apps that depend on .env
files but don't validate if all the necessary variables have been defined correctly.
Instead of having to document and validate this manually, I prefer to commit a self-documenting .env.example
file that may have placeholder or example values filled in. This can be used as a template or starting point for an actual .env
file.
FAQs
Load environment variables from .env and ensure they are defined
The npm package dotenv-safe receives a total of 155,928 weekly downloads. As such, dotenv-safe popularity was classified as popular.
We found that dotenv-safe demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
TC39 advances 11 JavaScript proposals, with two moving to Stage 4, bringing better math, binary APIs, and more features one step closer to the ECMAScript spec.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.