🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

cfgzen

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
Malware was recently detected in this package.

Affected versions:

1.0.01.0.11.0.21.0.31.0.4
+2 more

cfgzen

Lightweight .env and config file parser with native Rust acceleration

pipPyPI
Version
1.0.6
Weekly downloads
0
Maintainers
1
Weekly downloads
 

dotcfg

PyPI version Python License: MIT

Lightweight .env and config file parser with native Rust acceleration.

A batteries-included environment configuration library for Python. Parse .env files 10x faster than pure-Python alternatives with built-in validation, schema definitions, and secret masking.

Features

  • Native Rust parser — 10x faster than python-dotenv for large files
  • Variable interpolation${VAR}, $VAR, ${VAR:-default}
  • Type castingget("PORT", cast=int) with bool/int/float/custom
  • Schema validation — Declarative variable definitions with constraints
  • Secret masking — Safely log env vars without leaking credentials
  • CLI toolsdotcfg check, dotcfg diff, dotcfg keys
  • Full type annotations — py.typed, mypy-strict compatible

Installation

pip install dotcfg

Quick Start

from dotcfg import load, get

# Load .env into os.environ
env = load()

# Type-safe access
port = get("PORT", cast=int, default=8080)
debug = get("DEBUG", cast=bool, default=False)
db_url = get("DATABASE_URL")

Advanced Usage

EnvCore Class

from dotcfg import EnvCore

core = EnvCore(".env.production", override=True, interpolate=True)
env = core.load()

# Typed access with defaults
port = core.get("PORT", cast=int, default=8080)
host = core.get("HOST", default="0.0.0.0")

Schema Validation

Define expected variables with types, constraints, and documentation:

from dotcfg.schema import EnvSchema, Var
from dotcfg.validators import Url, Port, OneOf, MinLength

schema = EnvSchema(
    Var("DATABASE_URL", validators=[Url()], required=True,
        description="PostgreSQL connection string"),
    Var("PORT", cast=int, default="8080", validators=[Port()]),
    Var("LOG_LEVEL", default="info",
        validators=[OneOf(["debug", "info", "warning", "error"])]),
    Var("SECRET_KEY", required=True, sensitive=True,
        validators=[MinLength(32)]),
    Var("DEBUG", cast=bool, default="false"),
)

# Validate all at once
config = schema.validate()

# Access typed values
config.PORT        # int: 8080
config.DEBUG       # bool: False
config.LOG_LEVEL   # str: "info"

# Safe representation (sensitive values masked)
print(config)  # Config(PORT=8080, SECRET_KEY=********, ...)

# Generate .env.example template
print(schema.generate_template())

Secret Masking

Prevent accidental credential leaks in logs:

from dotcfg.vault import SecretVault

vault = SecretVault()

# Mask sensitive keys automatically
safe_env = vault.mask_dict(os.environ)
print(safe_env["AWS_SECRET_ACCESS_KEY"])  # "aws****key"

# Scrub URLs in log messages
msg = vault.scrub("Failed: postgres://admin:s3cr3t@db.host/app")
print(msg)  # "Failed: postgres://admin:****@db.host/app"

Validators

Built-in validators for common patterns:

from dotcfg.validators import (
    Required, Url, Port, Email, OneOf,
    Range, Regex, Boolean, IPv4, MinLength, Json,
)

# Use standalone
Port().validate("PORT", "8080")       # OK
Email().validate("ADMIN", "bad")      # raises ValidationError

# Or with schema
Var("REDIS_URL", validators=[Url(schemes=["redis", "rediss"])])
Var("WORKERS", cast=int, validators=[Range(min_val=1, max_val=32)])
Var("CONFIG", validators=[Json()])

CLI Tools

# Validate a .env file
$ dotcfg check .env
OK: .env (12 variables)

# Compare environments
$ dotcfg diff .env .env.production --mask
Only in .env:
  - DEV_MODE=true

Changed:
  ~ PORT: '3000' -> '80'
  ~ DATABASE_URL: 'pos****cal' -> 'pos****ion'

# List all keys
$ dotcfg keys .env --sort

.env File Format

# Comments
DATABASE_URL=postgres://localhost/mydb
PORT=8080

# Quoted values (single, double, backtick)
MESSAGE="Hello, World!"
SINGLE='no interpolation here'

# Variable interpolation
BASE_URL=https://api.example.com
ENDPOINT=${BASE_URL}/v2/users

# Default values
CACHE_TTL=${REDIS_TTL:-3600}

# Export prefix (compatible with shell source)
export API_KEY=sk_live_abc123

# Multiline (double-quoted)
RSA_KEY="-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA...
-----END RSA PRIVATE KEY-----"

Benchmarks

Parsing a 500-line .env file (averaged over 1000 runs):

LibraryTimeRelative
dotcfg (native)0.12ms1x
python-dotenv1.24ms10.3x slower
environs1.89ms15.8x slower
pydantic-settings2.41ms20.1x slower

Comparison with Alternatives

Featuredotcfgpython-dotenvenvironspydantic-settings
Native parserRustPythonPythonPython
InterpolationYesYesNoNo
Schema validationBuilt-inNoMarshmallowPydantic
Secret maskingBuilt-inNoNoNo
CLI toolsYesCLINoNo
Type castingYesNoYesYes
Typed (py.typed)YesNoNoYes

License

MIT

Keywords

dotenv

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts