Add additional security and configuration tips to the runtime log (#884)
Dim the tips text from the main injection information text
constTIPS=['🔐 encrypt with dotenvx: https://dotenvx.com','🔐 prevent committing .env to code: https://dotenvx.com/precommit','🔐 prevent building .env in docker: https://dotenvx.com/prebuild','🛠️ run anywhere with `dotenvx run -- yourcommand`','⚙️ specify custom .env file path with { path: \'/custom/path/.env\' }','⚙️ enable debug logging with { debug: true }','⚙️ override existing env vars with { override: true }','⚙️ suppress all logs with { quiet: true }','⚙️ write to custom object with { processEnv: myObject }','⚙️ load multiple .env files with { path: [\'.env.local\', \'.env\'] }']
Default quiet to true – hiding the runtime log message (#874)
NOTICE: 17.0.0 will be released with quiet defaulting to false. Use config({ quiet: true }) to suppress.
And check out the new dotenvx. As coding workflows evolve and agents increasingly handle secrets, encrypted .env files offer a much safer way to deploy both agents and code together with secure secrets. Simply switch require('dotenv').config() for require('@​dotenvx/dotenvx').config().
The dotenvx README is viewed thousands of times DAILY on GitHub and NPM.
Sponsoring dotenv is a great way to get in front of developers and give back to the developer community at the same time.
🐞 Fix recent regression when using path option. return to historical behavior: do not attempt to auto find .env if path set. (regression was introduced in 16.4.3) #814
🐞 Fix recent regression when using path option. return to historical behavior: do not attempt to auto find .env if path set. (regression was introduced in 16.4.3) #814
Removed browser keys for path, os, and crypto in package.json. These were set to false incorrectly as of 16.1. Instead, if using dotenv on the front-end make sure to include polyfills for path, os, and crypto. node-polyfill-webpack-plugin provides these.
ℹ️.env.vault extends the .env file format standard with a localized encrypted vault file. Package it securely with your production code deploys. It's cloud agnostic so that you can deploy your secrets anywhere – without risky third-party integrations. read more
Changed
Fixed "cannot resolve 'fs'" error on tools like Replit #693
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [dotenv](https://github.com/motdotla/dotenv) | dependencies | major | [`^16.0.0` -> `^17.0.0`](https://renovatebot.com/diffs/npm/dotenv/16.0.0/17.2.0) |
---
### Release Notes
<details>
<summary>motdotla/dotenv (dotenv)</summary>
### [`v17.2.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1720-2025-07-09)
[Compare Source](https://github.com/motdotla/dotenv/compare/v17.1.0...v17.2.0)
##### Added
- Optionally specify `DOTENV_CONFIG_QUIET=true` in your environment or `.env` file to quiet the runtime log ([#​889](https://github.com/motdotla/dotenv/pull/889))
- Just like dotenv any `DOTENV_CONFIG_` environment variables take precedence over any code set options like `({quiet: false})`
```ini
```
### [`v17.1.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1710-2025-07-07)
[Compare Source](https://github.com/motdotla/dotenv/compare/v17.0.1...v17.1.0)
##### Added
- Add additional security and configuration tips to the runtime log ([#​884](https://github.com/motdotla/dotenv/pull/884))
- Dim the tips text from the main injection information text
```js
const TIPS = [
'🔐 encrypt with dotenvx: https://dotenvx.com',
'🔐 prevent committing .env to code: https://dotenvx.com/precommit',
'🔐 prevent building .env in docker: https://dotenvx.com/prebuild',
'🛠️ run anywhere with `dotenvx run -- yourcommand`',
'⚙️ specify custom .env file path with { path: \'/custom/path/.env\' }',
'⚙️ enable debug logging with { debug: true }',
'⚙️ override existing env vars with { override: true }',
'⚙️ suppress all logs with { quiet: true }',
'⚙️ write to custom object with { processEnv: myObject }',
'⚙️ load multiple .env files with { path: [\'.env.local\', \'.env\'] }'
]
```
### [`v17.0.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1701-2025-07-01)
[Compare Source](https://github.com/motdotla/dotenv/compare/v17.0.0...v17.0.1)
##### Changed
- Patched injected log to count only populated/set keys to process.env ([#​879](https://github.com/motdotla/dotenv/pull/879))
### [`v17.0.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1700-2025-06-27)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.6.1...v17.0.0)
##### Changed
- Default `quiet` to false - informational (file and keys count) runtime log message shows by default ([#​875](https://github.com/motdotla/dotenv/pull/874))
### [`v16.6.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1661-2025-06-27)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.6.0...v16.6.1)
##### Changed
- Default `quiet` to true – hiding the runtime log message ([#​874](https://github.com/motdotla/dotenv/pull/874))
- NOTICE: 17.0.0 will be released with quiet defaulting to false. Use `config({ quiet: true })` to suppress.
- And check out the new [dotenvx](https://github.com/dotenvx/dotenvx). As coding workflows evolve and agents increasingly handle secrets, encrypted .env files offer a much safer way to deploy both agents and code together with secure secrets. Simply switch `require('dotenv').config()` for `require('@​dotenvx/dotenvx').config()`.
### [`v16.6.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1660-2025-06-26)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.5.0...v16.6.0)
##### Added
- Default log helpful message `[dotenv@16.6.0] injecting env (1) from .env` ([#​870](https://github.com/motdotla/dotenv/pull/870))
- Use `{ quiet: true }` to suppress
- Aligns dotenv more closely with [dotenvx](https://github.com/dotenvx/dotenvx).
### [`v16.5.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1650-2025-04-07)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.7...v16.5.0)
##### Added
- 🎉 Added new sponsor [Graphite](https://graphite.dev/?utm_source=github\&utm_medium=repo\&utm_campaign=dotenv) - *the AI developer productivity platform helping teams on GitHub ship higher quality software, faster*.
> \[!TIP]
> **[Become a sponsor](https://github.com/sponsors/motdotla)**
>
> The dotenvx README is viewed thousands of times DAILY on GitHub and NPM.
> Sponsoring dotenv is a great way to get in front of developers and give back to the developer community at the same time.
##### Changed
- Remove `_log` method. Use `_debug` [#​862](https://github.com/motdotla/dotenv/pull/862)
### [`v16.4.7`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1647-2024-12-03)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.6...v16.4.7)
##### Changed
- Ignore `.tap` folder when publishing. (oops, sorry about that everyone. - [@​motdotla](https://github.com/motdotla)) [#​848](https://github.com/motdotla/dotenv/pull/848)
### [`v16.4.6`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1646-2024-12-02)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.5...v16.4.6)
##### Changed
- Clean up stale dev dependencies [#​847](https://github.com/motdotla/dotenv/pull/847)
- Various README updates clarifying usage and alternative solutions using [dotenvx](https://github.com/dotenvx/dotenvx)
### [`v16.4.5`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1645-2024-02-19)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.4...v16.4.5)
##### Changed
- 🐞 Fix recent regression when using `path` option. return to historical behavior: do not attempt to auto find `.env` if `path` set. (regression was introduced in `16.4.3`) [#​814](https://github.com/motdotla/dotenv/pull/814)
### [`v16.4.4`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1644-2024-02-13)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.3...v16.4.4)
##### Changed
- 🐞 Replaced chaining operator `?.` with old school `&&` (fixing node 12 failures) [#​812](https://github.com/motdotla/dotenv/pull/812)
### [`v16.4.3`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1645-2024-02-19)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.2...v16.4.3)
##### Changed
- 🐞 Fix recent regression when using `path` option. return to historical behavior: do not attempt to auto find `.env` if `path` set. (regression was introduced in `16.4.3`) [#​814](https://github.com/motdotla/dotenv/pull/814)
### [`v16.4.2`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1642-2024-02-10)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.1...v16.4.2)
##### Changed
- Changed funding link in package.json to [`dotenvx.com`](https://dotenvx.com)
### [`v16.4.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1641-2024-01-24)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.4.0...v16.4.1)
- Patch support for array as `path` option [#​797](https://github.com/motdotla/dotenv/pull/797)
### [`v16.4.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1640-2024-01-23)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.3.2...v16.4.0)
- Add `error.code` to error messages around `.env.vault` decryption handling [#​795](https://github.com/motdotla/dotenv/pull/795)
- Add ability to find `.env.vault` file when filename(s) passed as an array [#​784](https://github.com/motdotla/dotenv/pull/784)
### [`v16.3.2`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1632-2024-01-18)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.3.1...v16.3.2)
##### Added
- Add debug message when no encoding set [#​735](https://github.com/motdotla/dotenv/pull/735)
##### Changed
- Fix output typing for `populate` [#​792](https://github.com/motdotla/dotenv/pull/792)
- Use subarray instead of slice [#​793](https://github.com/motdotla/dotenv/pull/793)
### [`v16.3.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1631-2023-06-17)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.3.0...v16.3.1)
##### Added
- Add missing type definitions for `processEnv` and `DOTENV_KEY` options. [#​756](https://github.com/motdotla/dotenv/pull/756)
### [`v16.3.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1630-2023-06-16)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.2.0...v16.3.0)
##### Added
- Optionally pass `DOTENV_KEY` to options rather than relying on `process.env.DOTENV_KEY`. Defaults to `process.env.DOTENV_KEY` [#​754](https://github.com/motdotla/dotenv/pull/754)
### [`v16.2.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1620-2023-06-15)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.1.4...v16.2.0)
##### Added
- Optionally write to your own target object rather than `process.env`. Defaults to `process.env`. [#​753](https://github.com/motdotla/dotenv/pull/753)
- Add import type URL to types file [#​751](https://github.com/motdotla/dotenv/pull/751)
### [`v16.1.4`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1614-2023-06-04)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.1.3...v16.1.4)
##### Added
- Added `.github/` to `.npmignore` [#​747](https://github.com/motdotla/dotenv/pull/747)
### [`v16.1.3`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1613-2023-05-31)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.1.2...v16.1.3)
##### Removed
- Removed `browser` keys for `path`, `os`, and `crypto` in package.json. These were set to false incorrectly as of 16.1. Instead, if using dotenv on the front-end make sure to include polyfills for `path`, `os`, and `crypto`. [node-polyfill-webpack-plugin](https://github.com/Richienb/node-polyfill-webpack-plugin) provides these.
### [`v16.1.2`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1612-2023-05-31)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.1.1...v16.1.2)
##### Changed
- Exposed private function `_configDotenv` as `configDotenv`. [#​744](https://github.com/motdotla/dotenv/pull/744)
### [`v16.1.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1611-2023-05-30)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.1.0...v16.1.1)
##### Added
- Added type definition for `decrypt` function
##### Changed
- Fixed `{crypto: false}` in `packageJson.browser`
### [`v16.1.0`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1610-2023-05-30)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.0.3...v16.1.0)
##### Added
- Add `populate` convenience method [#​733](https://github.com/motdotla/dotenv/pull/733)
- Accept URL as path option [#​720](https://github.com/motdotla/dotenv/pull/720)
- Add dotenv to `npm fund` command
- Spanish language README [#​698](https://github.com/motdotla/dotenv/pull/698)
- Add `.env.vault` support. 🎉 ([#​730](https://github.com/motdotla/dotenv/pull/730))
ℹ️ `.env.vault` extends the `.env` file format standard with a localized encrypted vault file. Package it securely with your production code deploys. It's cloud agnostic so that you can deploy your secrets anywhere – without [risky third-party integrations](https://techcrunch.com/2023/01/05/circleci-breach/). [read more](https://github.com/motdotla/dotenv#-deploying)
##### Changed
- Fixed "cannot resolve 'fs'" error on tools like Replit [#​693](https://github.com/motdotla/dotenv/pull/693)
### [`v16.0.3`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1603-2022-09-29)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.0.2...v16.0.3)
##### Changed
- Added library version to debug logs ([#​682](https://github.com/motdotla/dotenv/pull/682))
### [`v16.0.2`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1602-2022-08-30)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.0.1...v16.0.2)
##### Added
- Export `env-options.js` and `cli-options.js` in package.json for use with downstream [dotenv-expand](https://github.com/motdotla/dotenv-expand) module
### [`v16.0.1`](https://github.com/motdotla/dotenv/blob/HEAD/CHANGELOG.md#1601-2022-05-10)
[Compare Source](https://github.com/motdotla/dotenv/compare/v16.0.0...v16.0.1)
##### Changed
- Minor README clarifications
- Development ONLY: updated devDependencies as recommended for development only security risks ([#​658](https://github.com/motdotla/dotenv/pull/658))
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4zOC4yIiwidXBkYXRlZEluVmVyIjoiNDEuMzguMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6W119-->
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
any of the package files in this branch needs updating, or
the branch becomes conflicted, or
you click the rebase/retry checkbox if found above, or
you rename this PR's title to start with "rebase!" to trigger it manually
The artifact failure details are included below:
File name: package-lock.json
npm ERR! Invalid Version: >=4.5.1
npm ERR! A complete log of this run can be found in:
npm ERR! /tmp/renovate/cache/others/npm/_logs/2025-07-19T14_03_46_083Z-debug-0.log
### ⚠️ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
- any of the package files in this branch needs updating, or
- the branch becomes conflicted, or
- you click the rebase/retry checkbox if found above, or
- you rename this PR's title to start with "rebase!" to trigger it manually
The artifact failure details are included below:
##### File name: package-lock.json
```
npm ERR! Invalid Version: >=4.5.1
npm ERR! A complete log of this run can be found in:
npm ERR! /tmp/renovate/cache/others/npm/_logs/2025-07-19T14_03_46_083Z-debug-0.log
```
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️Warning: custom changes will be lost.
### Edited/Blocked Notification
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️ **Warning**: custom changes will be lost.
This repo is archived. You cannot comment on pull requests.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
^16.0.0->^17.0.0Release Notes
motdotla/dotenv (dotenv)
v17.2.0Compare Source
Added
DOTENV_CONFIG_QUIET=truein your environment or.envfile to quiet the runtime log (#889)DOTENV_CONFIG_environment variables take precedence over any code set options like({quiet: false})v17.1.0Compare Source
Added
v17.0.1Compare Source
Changed
v17.0.0Compare Source
Changed
quietto false - informational (file and keys count) runtime log message shows by default (#875)v16.6.1Compare Source
Changed
quietto true – hiding the runtime log message (#874)config({ quiet: true })to suppress.require('dotenv').config()forrequire('@​dotenvx/dotenvx').config().v16.6.0Compare Source
Added
[dotenv@16.6.0] injecting env (1) from .env(#870){ quiet: true }to suppressv16.5.0Compare Source
Added
Changed
_logmethod. Use_debug#862v16.4.7Compare Source
Changed
.tapfolder when publishing. (oops, sorry about that everyone. - @motdotla) #848v16.4.6Compare Source
Changed
v16.4.5Compare Source
Changed
pathoption. return to historical behavior: do not attempt to auto find.envifpathset. (regression was introduced in16.4.3) #814v16.4.4Compare Source
Changed
?.with old school&&(fixing node 12 failures) #812v16.4.3Compare Source
Changed
pathoption. return to historical behavior: do not attempt to auto find.envifpathset. (regression was introduced in16.4.3) #814v16.4.2Compare Source
Changed
dotenvx.comv16.4.1Compare Source
pathoption #797v16.4.0Compare Source
error.codeto error messages around.env.vaultdecryption handling #795.env.vaultfile when filename(s) passed as an array #784v16.3.2Compare Source
Added
Changed
populate#792v16.3.1Compare Source
Added
processEnvandDOTENV_KEYoptions. #756v16.3.0Compare Source
Added
DOTENV_KEYto options rather than relying onprocess.env.DOTENV_KEY. Defaults toprocess.env.DOTENV_KEY#754v16.2.0Compare Source
Added
process.env. Defaults toprocess.env. #753v16.1.4Compare Source
Added
.github/to.npmignore#747v16.1.3Compare Source
Removed
browserkeys forpath,os, andcryptoin package.json. These were set to false incorrectly as of 16.1. Instead, if using dotenv on the front-end make sure to include polyfills forpath,os, andcrypto. node-polyfill-webpack-plugin provides these.v16.1.2Compare Source
Changed
_configDotenvasconfigDotenv. #744v16.1.1Compare Source
Added
decryptfunctionChanged
{crypto: false}inpackageJson.browserv16.1.0Compare Source
Added
populateconvenience method #733npm fundcommand.env.vaultsupport. 🎉 (#730)ℹ️
.env.vaultextends the.envfile format standard with a localized encrypted vault file. Package it securely with your production code deploys. It's cloud agnostic so that you can deploy your secrets anywhere – without risky third-party integrations. read moreChanged
v16.0.3Compare Source
Changed
v16.0.2Compare Source
Added
env-options.jsandcli-options.jsin package.json for use with downstream dotenv-expand modulev16.0.1Compare Source
Changed
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
⚠️ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below:
File name: package-lock.json
Edited/Blocked Notification
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️ Warning: custom changes will be lost.