NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #140 most downloaded on npm
Loads environment variables from .env file
Last release 4 days ago
30 Sep 2026
Release timing varies
gaps range from 1 weeks to 5 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
110 releases · first in 2013
Fix missing typescript module declaration
import dotenv/config should default quiet: true
import dotenv/config should default quiet: true (#1063)One column per quarter.
Patch DOTENV_QUIET setting when inside .env file
DOTENV_QUIET setting when inside .env file (#1059)perf: skip quoted text and short-circuit ASCII whitespace checks
perf: skip quoted text and short-circuit ASCII whitespace checks
Handle file urls in config logging
`sh $ dotenv run -- node index.js ◇ injected env (2) from .env Hello Dotenv `
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv
faster than Node native parseEnv!
Improved skill files - tightened up details
Change text injecting to injected
injecting to injected (#1005)Add skills/ folder with focused agent skills: skills/dotenv/SKILL.md (core usage) and skills/dotenvx/SKILL.md (encryption, multiple environments, vari
skills/ folder with focused agent skills: skills/dotenv/SKILL.md (core usage) and skills/dotenvx/SKILL.md (encryption, multiple environments, variable expansion) for AI coding agent discovery via the skills.sh ecosystem (npx skills add motdotla/dotenv)◇ injecting env (14) from .env (#1003)Fix as2 example command in README and update spanish README
Add a new README section on dotenv’s approach to the agentic future.
Make DotenvPopulateInput accept NodeJS.ProcessEnv type
Fixed typescript error definition
🙏 A big thank you to new sponsor Tuple.app - *the premier screen sharing app for developers on macOS and Windows.* Go check them out. It's wonderful a
Fix clickable tip links by removing parentheses
Optionally specify DOTENV_CONFIG_QUIET=true in your environment or .env file to quiet the runtime log
DOTENV_CONFIG_QUIET=true in your environment or .env file to quiet the runtime log (#889)DOTENV_CONFIG_ environment variables take precedence over any code set options like ({quiet: false})# .env
DOTENV_CONFIG_QUIET=true
HELLO="World"
// index.js
require('dotenv').config()
console.log(`Hello ${process.env.HELLO}`)
$ node index.js
Hello World
or
$ DOTENV_CONFIG_QUIET=true node index.js
Add additional security and configuration tips to the runtime log
const TIPS = [
'🔐 encrypt with dotenvx: https://dotenvx.com',
'🔐 prevent committing .env to code: https://dotenvx.com/precommit',
'🔐 prevent building .env in docker: https://dotenvx.com/prebuild',
'🛠️ run anywhere with `dotenvx run -- yourcommand`',
'⚙️ specify custom .env file path with { path: \'/custom/path/.env\' }',
'⚙️ enable debug logging with { debug: true }',
'⚙️ override existing env vars with { override: true }',
'⚙️ suppress all logs with { quiet: true }',
'⚙️ write to custom object with { processEnv: myObject }',
'⚙️ load multiple .env files with { path: [\'.env.local\', \'.env\'] }'
]
Patched injected log to count only populated/set keys to process.env
Default quiet to false - informational (file and keys count) runtime log message shows by default
quiet to false - informational (file and keys count) runtime log message shows by default (#875)Default quiet to true – hiding the runtime log message
quiet to true – hiding the runtime log message (#874)config({ quiet: true }) to suppress.require('dotenv').config() for require('@dotenvx/dotenvx').config().Default log helpful message [dotenv@16.6.0] injecting env (1) from .env
🎉 Added new sponsor Graphite - *the AI developer productivity platform helping teams on GitHub ship higher quality software, faster*.
[!TIP] Become a sponsor
The dotenvx README is viewed thousands of times DAILY on GitHub and NPM. Sponsoring dotenv is a great way to get in front of developers and give back to the developer community at the same time.
_log method. Use _debug #862Ignore .tap folder when publishing. (oops, sorry about that everyone. - @motdotla) #848
.tap folder when publishing. (oops, sorry about that everyone. - @motdotla) #848Clean up stale dev dependencies #847
🐞 Fix recent regression when using path option. return to historical behavior: do not attempt to auto find .env if path set. (regression was introduce
path option. return to historical behavior: do not attempt to auto find .env if path set. (regression was introduced in 16.4.3) #814🐞 Replaced chaining operator ?. with old school && (fixing node 12 failures) #812
?. with old school && (fixing node 12 failures) #812Fixed processing of multiple files in options.path #805
options.path #805Changed funding link in package.json to `dotenvx.com`
dotenvx.comPatch support for array as path option #797
path option #797Add error.code to error messages around .env.vault decryption handling #795
Add debug message when no encoding set #735
Add missing type definitions for processEnv and DOTENV_KEY options. #756
processEnv and DOTENV_KEY options. #756Optionally pass DOTENV_KEY to options rather than relying on process.env.DOTENV_KEY. Defaults to process.env.DOTENV_KEY #754
DOTENV_KEY to options rather than relying on process.env.DOTENV_KEY. Defaults to process.env.DOTENV_KEY #754Optionally write to your own target object rather than process.env. Defaults to process.env. #753
Added .github/ to .npmignore #747
.github/ to .npmignore #747Removed browser keys for path, os, and crypto in package.json. These were set to false incorrectly as of 16.1. Instead, if using dotenv on the front-e
browser keys for path, os, and crypto in package.json. These were set to false incorrectly as of 16.1. Instead, if using dotenv on the front-end make sure to include polyfills for path, os, and crypto. node-polyfill-webpack-plugin provides these.Exposed private function _configDotenv as configDotenv. #744
_configDotenv as configDotenv. #744Added type definition for decrypt function
decrypt function{crypto: false} in packageJson.browserAdd populate convenience method #733
populate convenience method #733npm fund command.env.vault support. 🎉 (#730)ℹ️ .env.vault extends the .env file format standard with a localized encrypted vault file. Package it securely with your production code deploys. It's cloud agnostic so that you can deploy your secrets anywhere – without risky third-party integrations. read more
Nothing published for this version
Nothing published for this version
Added library version to debug logs
Export env-options.js and cli-options.js in package.json for use with downstream dotenv-expand module
env-options.js and cli-options.js in package.json for use with downstream dotenv-expand moduleDevelopment ONLY: updated devDependencies as recommended for development only security risks
If you had values containing the backtick character, please quote those values with either single or double quotes.
If you had values containing the backtick character, please quote those values with either single or double quotes.
Properly parse empty single or double quoted values 🐞
v15.0.0 is a major new release with some important breaking changes.
v15.0.0 is a major new release with some important breaking changes.
# marks the beginning of a comment (UNLESS the value is wrapped in quotes. Please update your .env files to wrap in quotes any values containing #. For example: SECRET_HASH="something-with-a-#-hash")...Understandably, (as some teams have noted) this is tedious to do across the entire team. To make it less tedious, we recommend using dotenv cli going forward. It's an optional plugin that will keep your .env files in sync between machines, environments, or team members.
Preserve backwards compatibility on values containing # 🐞
# 🐞 (#603)Preserve backwards compatibility on exports by re-introducing the prior in-place exports 🐞
### Added - Add multiline option 🎉
multiline option 🎉 (#486)Add dotenv_config_override cli option
dotenv_config_override cli optionDOTENV_CONFIG_OVERRIDE command line env optionAdd React gotcha to FAQ on README
### Added - Add override option 🎉
override option 🎉 (#595)Log error on failure to load .env file
.env file (#594)_Breaking:_ Support inline comments for the parser 🎉
Hide comments and newlines from debug output
_Breaking:_ Add type file for config.js
config.js (#539)Minor order adjustment to package json format
Simplified jsdoc for consistency across editors
Improve embedded jsdoc type documentation
Your coding agent can read these notes before it upgrades. Set up the MCP server →