Skip to content
CAI
Software that uses CAICheck a score

bkeepers/dotenv

67.8

Adequate · 26 September 2026

699

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add dotenv executable entry point

A new executable script has been added to the bin directory, serving as the entry point for the dotenv CLI. This script loads the Ruby environment and invokes the existing Dotenv::CLI class, allowing users to run the tool directly from the command line.

bin · high confidence

Support for shell command and variable substitution in dotenv values

The dotenv library now supports dynamic value substitution for both shell commands and environment variables within .env files. Users can now use syntax like \$(command)\ to execute shell commands and interpolate their output, as well as reference other variables (e.g., \https://$HOST\) with proper escaping and precedence handling. This enables more flexible configuration patterns where values are computed at load time.

lib/dotenv/substitutions · high confidence

Behavioural changes

Adopts StandardRB and updates project configuration files

The project has migrated from Rubocop to StandardRB for code style enforcement, reflected in the new .standard.yml configuration and updated Rakefile tasks. Additionally, the repository now includes a .gitignore with updated exclusions (e.g., .ruby-version, tmp, vendor), a Guardfile for automated test running, and an OWNERS file defining project maintainers.

(repo-wide) · high confidence

Major refactor of the dotenv library with new modular architecture

The library has been restructured into a modular architecture, introducing new classes such as a dedicated Parser, CLI, Diff, and LogSubscriber. The Rails integration is now handled by a new \Dotenv::Rails\ class (replacing the old \Dotenv::Railtie\), which supports environment-specific files, automatic ENV restoration in test suites, and logging of loaded variables. The CLI now supports an \--overwrite\ flag and template generation, while the core \Environment\ class now delegates parsing to the new \Parser\ class, allowing for more robust handling of variable substitution and line break modes.

lib/dotenv · high confidence

Refactor Dotenv API and add thread-safe modification

The Dotenv module was refactored to support multiple filenames, variable overwrite modes, and thread-safe environment modification. Users can now pass multiple files to \Dotenv.load\ and control overwrite behavior via the \overwrite\ option. A new \Dotenv.modify\ method was added to safely update ENV variables within a block using a monitor for thread safety. Additionally, \Dotenv.parse\ was introduced to allow custom processing of parsed environment variables, and the internal API was restructured to reduce duplication and improve clarity.

lib · medium confidence

Test coverage

Added benchmark scripts for parsing performance; Added comprehensive test coverage for CLI, parser, and Rails integration; Added test coverage for ENV variable restoration; Expanded test coverage for Dotenv load and overwrite behaviors; Updated test fixtures for .env file parsing.

Dependencies

Rails integration and Ruby version requirements updated

The dotenv-rails gem is now a separate package that depends on railties \>= 6.1, allowing Rails 6.1, 7.0, and 7.1 applications to use dotenv. The main dotenv gem now requires Ruby 3.0 or higher and includes metadata for changelog and funding links. Development dependencies have been updated to include rake, standard, and other testing tools.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 44 → 68 (+24.0)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 61 → 61 (+0.0)
  • Readiness 30 → 75 (+45.2)
  • Security 43 → 77 (+33.6)

Resolved (12)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The README does not mention how to handle .env files for non-development environments (e.g., staging, production) and whether dotenv loads them in those contexts. (README.md)

New (6)

  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • PR-triggered workflow without a permissions block

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bkeepers/dotenv was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 34156bf400cd67387fa6ed9f146778f6a2f5f743 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.