Skip to content
CAI
Software that uses CAICheck a score

motdotla/dotenv

49.0

Weak · 1 October 2026

840

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the dotenv library, which provides functionality for loading environment variables from .env files into Node.js applications. It exposes a programmatic API for configuration and parsing, alongside a CLI tool for executing commands with injected environment variables. The implementation includes a high-performance parser, robust Windows command spawning, and comprehensive TypeScript type definitions.

Features

Added build and performance benchmark scripts

The project now includes a \scripts/build.js\ file that bundles the library using esbuild for Node 12+ and a \scripts/parse-perf.js\ script that benchmarks the new 'fast' parser against the classic and native implementations to ensure a minimum 1.5x speedup.

scripts · high confidence

New CLI for running commands with .env variables

Dotenv now includes a command-line interface (CLI) that allows you to run any command with environment variables loaded from a .env file. You can use \npx dotenv run -- node index.js\ to execute your application with the environment variables injected, or use the \--fast\ flag to opt-in to a faster character-scanner parser for improved performance on large files.

(repo-wide) · high confidence

New configuration options and Windows command spawning support

The library now supports configuring behavior via environment variables (DOTENV\CONFIG\\*) and introduces a new \fast\ parser option for improved performance. A new \config-options.js\ module handles parsing these environment variables, while \main.d.ts\ updates the TypeScript definitions to include the new \fast\, \override\, and \processEnv\ options. Additionally, a new \spawn-command.js\ module provides robust Windows command execution, handling argument quoting and shell protection for batch files and npm shims.

lib · high confidence

Test coverage

Added TypeScript type tests for dotenv API; Expanded test coverage for parsing, CLI, and configuration behavior; Removed legacy test suite for dotenv.load().

Dependencies

dotenv v18.0.5 release with modern build tooling and TypeScript support

The dotenv package has been updated to version 18.0.5, introducing a comprehensive rebuild of its development and distribution infrastructure. The build system now uses esbuild to compile output into the dist/ directory, replacing the previous lib/ structure. This change brings native TypeScript support, exposing type definitions via the new 'types' field and explicit 'exports' map for both the main module and the './config' entry point. The test suite has migrated from Mocha to Tap, and linting is handled by Standard. Additionally, the package now enforces a minimum Node.js version of 12 and includes a 'browser' field that disables the 'fs' module to prevent errors in browser environments.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 49 (-5.4)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 57 → 52 (-4.7)
  • Architecture 69 → 69 (+0.0)
  • Maturity 48 → 49 (+0.7)
  • Readiness 55 → 42 (-12.4)
  • Security 85 → 90 (+4.7)
  • Performance 60 (new)

Resolved (11)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Off-boarding risk: anonymized user #1
  • main.populate (cognitive 18) (lib/main.js)

New (10)

  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
  • FunctionTooLong: main.parseFast (lib/main.js)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Off-boarding risk: anonymized user #1
  • Repeated repair: tests/test-parse-fast.js (tests/test-parse-fast.js)
  • cli.run (cyclomatic 27) (cli.js)
  • populate (cognitive 21) (lib/main.js)
  • run (cognitive 36) (cli.js)

Changes since last survey

  • 62 commits — 50 feature/other, 12 fixes

By area

  • (root) — 34 commits
  • (repo) — 13 commits
  • lib/main.js — 9 commits
  • tests/test-parse-fast.js — 2 commits
  • .github/workflows — 1 commit
  • lib/config-options.js — 1 commit
  • lib/spawn-command.js — 1 commit
  • tests/test-config-quiet.js — 1 commit

Notable commits

  • fix: Merge pull request #1049 from webdevelopersrinu/fix-populate-null
  • fix: Merge pull request #1051 from hxperl/fix-dotenv-error-code-type
  • fix: Merge pull request #1054 from jakezwang/fix-url-path-logging
  • fix: Merge pull request #1056 from motdotla/1043-fast-parser-regression-tests
  • fix: Merge pull request #1058 from SulimanAbdulrazzaq/fix/fast-parser-lone-export-line
  • fix: Merge pull request #1068 from matzehecht/fix-typescript
  • fix: fix: handle file URLs in config logging
  • fix: fix: handle parser regressions directly in the fast scanner
  • fix: fix: keep assignments after a bare export line in the fast parser
  • fix: fix: preserve classic parser behavior for fast parser edge cases
  • fix: fix: retain closing quote candidates in the fast scanner
  • fix: fix: scan colon separators, export keys and Unicode line endings
  • change: .cmd coverage
  • change: 18.0.0
  • change: 18.0.1
  • change: 18.0.3
  • change: 18.0.4
  • change: 18.0.5
  • change: Bound fast parser comment scans to the current line
  • change: Bump ip-address from 10.2.0 to 10.7.2
  • …and 42 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

motdotla/dotenv was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 05215e09b73575b6f8e272658ca7849685651384 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.