
Product
Rust Support Now in Beta
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.
Setup (after install):
npx env-assert
yarn env-assert
pnpm env-assert
This will create an example config file
env-assert.config.ts
Here you can setup your required and optional environment variables
import type { CreateEnvVarsType } from "env-assert";
const required = ["FOO"] as const;
const optional = ["BAR"] as const;
const config = {
required,
optional,
};
export default config;
export type EnvVars = CreateEnvVarsType<typeof config>;
Run env-assert before any script, for example:
yarn env-assert && yarn build
Pass the type of your config to CreateEnvVarsType to receive a type that you can use to extend ProcessEnv, so you know what variables are available. 👌
global.d.ts
import { EnvVars } from "./env-assert.config";
export declare global {
declare namespace NodeJS {
interface ProcessEnv extends EnvVars {}
}
}
FAQs
verify that environment variables exist before doing something
The npm package env-assert receives a total of 1,250 weekly downloads. As such, env-assert popularity was classified as popular.
We found that env-assert demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Product
Socket's Rust support is moving to Beta: all users can scan Cargo projects and generate SBOMs, including Cargo.toml-only crates, with Rust-aware supply chain checks.
Product
Socket Fix 2.0 brings targeted CVE remediation, smarter upgrade planning, and broader ecosystem support to help developers get to zero alerts.
Security News
Socket CEO Feross Aboukhadijeh joins Risky Business Weekly to unpack recent npm phishing attacks, their limited impact, and the risks if attackers get smarter.