NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1249 most downloaded on npm
Expand environment variables using dotenv
Last release 2 months ago
29 Jul 2026
Release timing varies
gaps range from 9 days to 1.2 years
Most releases are documented
notes for 24 of 30 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
30 releases · first in 2016
NEW 🎉: Command substitution and encryption are now supported automatically during expansion.
These improvements bring work developed in dotenvx to dotenv-expand through
@dotenvx/primitives.
- and +) and variables that are empty (:- and :+).Yes, the jump to major version 1000 is intentional. It looks cool and this release represents the biggest changes to dotenv-expand in 10 years - adding support for command substitution and decryption of encrypted .env files.
### Changed - bump dotenv to v17
One column per quarter.
🙏 A big thank you to new sponsor Tuple.app - *the premier screen sharing app for developers on macOS and Windows.* Go check them out. It's wonderful a
🎉 Added new sponsor Graphite - *the AI developer productivity platform helping teams on GitHub ship higher quality software, faster*.
[!TIP] Become a sponsor
The dotenvx-expand README is viewed thousands of times DAILY on GitHub and NPM. Sponsoring dotenv and dotenv-expand is a great way to get in front of developers and give back to the developer community at the same time.
break logic on runningParsed (#ad887)
🎉 support alternate value expansion (see usage)
NOTE: I recommend dotenvx over dotenv-expand when you are ready. I'm putting all my effort there for a unified standard .env implementation that works everywhere and matches bash, docker-compose, and more. In some cases it slightly improves on them - leading to more reliability for your secrets and config.
This has always been dangerous (unexpected side effects) and is now removed.
process.envshould not hold values you want to expand. If for some reason you need equivalent abilities, use dotenvx. You can ship an encrypted .env file with your code - allowing safe expansion at runtime - rather than relying on trying to expand pre-existingprocess.envvalues that could for good reason have a dollar sign in them (example a password).
🐞 fix self-expanding undefined variable with default value
### Changed - Fix .nyc_output in .npmignore
.nyc_output in .npmignore🐞 fix recursive expansion when expansion key is sourced from process.env
process.env (#121)🐞 fix recursive expansion when expansion keys in reverse order
🐞 bug fix when processEnv set to process.env rather than empty object (also test fixes which hid the bug)
processEnv set to process.env rather than empty object (also test fixes which hid the bug) (#113)Changed funding link in package.json to `dotenvx.com`
dotenvx.comAdded funding link in package.json
Add typings for import dotenv-expand/config
import dotenv-expand/config (#99)POSTGRESQL.BASE.USER (#93)processEnv option (#105)${VAR-default} (#109)process.env environment variables. NOTE: make sure to see updated README regarding dotenv.config({ processEnv: {} }) (#104)$var1$var2 (#103, #104)VAR=$VAR #98ignoreProcessEnv option (use processEnv option going forward)Support special characters in default expansion
Proper support for preload and cli args
### Changed - 🐞 Fixed defaults bug
### Changed - 🐞 Fixed preloading bug
Added config.js to package.json lookups
_Breaking:_ Bump to v16.0.0 of dotenv
_Breaking:_ Bump to v15.0.0 of dotenv
v15.0.0 of dotenv### Changed - Updated README
_Breaking_ Move default export to export of expand function (#14b1f2)
Please see commit history.
Please see commit history.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →