{"id":22362775,"url":"https://github.com/danmasta/config","last_synced_at":"2026-02-16T20:33:19.329Z","repository":{"id":57105740,"uuid":"100578430","full_name":"danmasta/config","owner":"danmasta","description":"Configuration helper for node apps","archived":false,"fork":false,"pushed_at":"2025-04-07T04:24:11.000Z","size":208,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-07-30T15:25:01.383Z","etag":null,"topics":["conf","config","env","environment","immutable"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/danmasta.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2017-08-17T08:08:48.000Z","updated_at":"2025-04-07T04:24:13.000Z","dependencies_parsed_at":"2024-03-25T07:25:12.391Z","dependency_job_id":"7c5cce54-6593-4235-bb67-0c079654c57d","html_url":"https://github.com/danmasta/config","commit_stats":{"total_commits":119,"total_committers":1,"mean_commits":119.0,"dds":0.0,"last_synced_commit":"43e916e02aded6da5a804b12bc0468319daee790"},"previous_names":[],"tags_count":18,"template":false,"template_full_name":null,"purl":"pkg:github/danmasta/config","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/danmasta%2Fconfig","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/danmasta%2Fconfig/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/danmasta%2Fconfig/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/danmasta%2Fconfig/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/danmasta","download_url":"https://codeload.github.com/danmasta/config/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/danmasta%2Fconfig/sbom","scorecard":{"id":321240,"data":{"date":"2025-08-11","repo":{"name":"github.com/danmasta/config","commit":"435ab74267159b1892b9266aed803f2e156c5668"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":3,"reason":"4 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":7,"reason":"3 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T01:24:42.592Z","repository_id":57105740,"created_at":"2025-08-18T01:24:42.593Z","updated_at":"2025-08-18T01:24:42.593Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29517613,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-16T18:37:19.720Z","status":"ssl_error","status_checked_at":"2026-02-16T18:36:46.920Z","response_time":115,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["conf","config","env","environment","immutable"],"created_at":"2024-12-04T17:11:42.224Z","updated_at":"2026-02-16T20:33:19.310Z","avatar_url":"https://github.com/danmasta.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Config\nConfiguration helper for node apps\n\n#### Features:\n* Easy to use\n* Load `.js`, `.json`, `.cjs`, or `.mjs` files\n* Exports plain javascript objects\n* Safe by default\n* Exported config is immutable and constant\n* Flexible configuration via environment variables or cmd args\n* Helps prevent many config related bugs and vulnerabilities\n* Native esm and cjs support\n* 0 external dependencies\n\n## About\nI wanted a better way to configure node apps. Other config packages out there were either too complex or not flexible enough. This package aims to be the simplest, most flexible config initializer possible. This package exports config at run time as an immutable constant object that cannot be modified. It helps prevent an entire class of possible hard to track down bugs from code that might accidentally or intentionally overwrite config values during execution. It can also help prevent a whole class of potential vulnerabilities via environment hijack/overwritting from bad dependecies. You can import env variables into your config files at startup time via this package and they now become immutable.\n\n## Usage\nAdd config as a dependency for your app and install via npm\n```bash\nnpm install config@danmasta/config --save\n```\nInstall a specific [version](https://github.com/danmasta/config/tags)\n```bash\nnpm install config@danmasta/config#v0.0.1 --save\n```\n\nImport or require the package in your app\n```js\nimport config from 'config';\n```\n\nGet values\n```js\nimport redis from 'redis';\nconst client = redis.createClient(config.redis);\n```\n\n### Options\nname | type | description\n-----|------|------------\n`enableArgv` | *`boolean`* | Whether or not to enable cli argv helper options. Default is `true`\n`enableEnv` | *`boolean`* | Whether or not to enable environment variable helper options. Default is `true`\n`setNodeEnv` | *`boolean`* | Whether or not to set the `NODE_ENV` environment variable if not already set. Default is `false`\n`dir` | *`string`* | Directory to load configuration files from. Default is `./config`\n`group` | *`string`* | Name of the config group file to load. This is a middle config file loaded in the chain. Default is `undefined`\n`config` | *`string`* | Name of the config file to load. This is a middle config file loaded in the chain. Default is `undefined`\n`id` | *`string`* | Name of the config ID to load. This is the last config file loaded so it's the most specific and will override all others in the chain. Default is `undefined`\n`defaultFileName` | *`string`* | Name of the default configuration file to load. This is the first file loaded for everything. Default is `default`\n`defaultNodeEnv` | *`string`* | Which env name to use if `setNodeEnv` is enabled. Default is `'development'`\n`warn` | *`boolean`* | If true will write a message to `stderr` when a config file is not found. Default is `false`\n`throw` | *`boolean`* | If true will throw an error when a config file is not found. Default is `false`\n`exts` | *`string\\|array`* | Which file extensions to use during file lookup. Default is `['.js', '.json', '.cjs', '.mjs']`\n`env` | *`string`* | Name of the environment file to load. This is the second config file loaded in the chain. Default is `undefined`\n\n### Methods\nName | Description\n-----|------------\n`resolve()` | Loads config asynchronously. Returns a promise that resolves with an immutable `object`\n`resolveSync()` | Loads config synchronously. Returns an immutable `object`\n\n### ENV / CMD options\nEnv Variable | Cmd Arg | Description\n-------------|---------|------------\n`CONFIG_DIR` | config-dir | Directory to load configuration files from. Default is `./config`\n`CONFIG_GROUP` | config-group | Name of the config group file to load. This is a middle config file loaded in the chain. Default is `undefined`\n`CONFIG` | config | Name of the config file to load. This is a middle config file loaded in the chain. Default is `undefined`\n`CONFIG_ID` | config-id | Name of the config ID to load. This is the last config file loaded so it's the most specific and will override all others in the chain. Default is `undefined`\n`NODE_ENV` | node-env | Name of the environment file to load. This is the second config file loaded in the chain. Default is `undefined`\n\n#### Example\nYou can pass config names as cmd arguments or env variables and they will be set as environment variables *before* config files are loaded. This means you can do things like:\n```bash\nnode app --config staging\n```\n```bash\nNODE_ENV=ci CONFIG=staging node app\n```\nThis will load both the default config and then the staging config. This makes it really easy to run and/or test your app with different configs in multiple environments\n\n## Config Files\nThis package will attempt to load configuration files in the following order:\n1. `./config/default`\n2. `./config/(NODE_ENV)`\n3. `./config/(CONFIG_GROUP)`\n4. `./config/(CONFIG)`\n5. `./config/(CONFIG_ID)`\n\nConfig files can be `.js`, `.json`, `.cjs`, or `.mjs` and they should export a plain object as default. They should also be named to match the options variable they represent, eg: `production.js` for `NODE_ENV=production` and `development.js` for `NODE_ENV=development`, etc. If you had a `CONFIG_GROUP=eu` variable set, for example, then you would also want to have an `eu.js` file.\n```js\nexport default {\n    redis: {\n        host: '127.0.0.1',\n        port: 6379\n    }\n};\n```\n*If multiple files are found, they are merged with the default configuration and values are over written. This means you only need to add properties that have changed between environments*\n\n## Safety\nAll objects exported from this package are immutable and constant by default. This means all own, inherited, and nested properties cannot be changed. Any attempt to assign or overwrite a property on the config object after export will [*`fail silently`*](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/freeze#description) or throw a `TypeError`\n\nIf you need to extend the config object or add/change values after initialization, you can create a new instance with your custom configuration, then call `resolve()` and export that to your application\n\n## Examples\n#### Set a property for two different environments\n```js\n// ./config/default.js\nexport default {\n    redis: {\n        host: 'redis.example.net',\n        port: 6379\n    }\n};\n\n// ./config/development.js\nexport default {\n    redis: {\n        host: '127.0.0.1'\n    }\n};\n```\n\n#### Get a property value\n*Config exports a plain javascript object, so you can just use dot notation to access any nested value*\n```js\nconfig.redis.host // '127.0.0.1' in development\nconfig.redis.port // 6379\n```\n\n#### Load config from a specific directory programatically\n```js\nimport { Config } from 'config';\n\nconst config = new Config({\n    dir: './test/config'\n});\n\nexport default await config.resolve();\n```\n\n#### Use [env](https://github.com/danmasta/env) variables with config for extra flexibility\n```js\nimport env from 'env';\n\n// ./config/default.js\nexport default {\n    redis: {\n        host: env('REDIS_HOST'),\n        port: env('REDIS_PORT')\n    }\n};\n```\n*You can now expose environment variables as native types and they become immutable as part of your config*\n\n## Testing\nTests are currently run using mocha and chai. To execute tests run `make test`. To generate unit test coverage reports run `make coverage`\n\n## Contact\nIf you have any questions feel free to get in touch\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdanmasta%2Fconfig","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdanmasta%2Fconfig","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdanmasta%2Fconfig/lists"}