{"id":42274205,"url":"https://github.com/stackus/dotenv","last_synced_at":"2026-01-27T07:38:08.915Z","repository":{"id":57651651,"uuid":"448217567","full_name":"stackus/dotenv","owner":"stackus","description":"Yet another dotenv Go port.","archived":false,"fork":false,"pushed_at":"2022-12-06T03:31:23.000Z","size":15,"stargazers_count":4,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"master","last_synced_at":"2024-04-28T07:44:54.791Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/stackus.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2022-01-15T08:05:32.000Z","updated_at":"2024-04-28T07:44:54.792Z","dependencies_parsed_at":"2023-01-23T07:30:23.665Z","dependency_job_id":null,"html_url":"https://github.com/stackus/dotenv","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/stackus/dotenv","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stackus%2Fdotenv","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stackus%2Fdotenv/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stackus%2Fdotenv/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stackus%2Fdotenv/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/stackus","download_url":"https://codeload.github.com/stackus/dotenv/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/stackus%2Fdotenv/sbom","scorecard":{"id":845472,"data":{"date":"2025-08-11","repo":{"name":"github.com/stackus/dotenv","commit":"02295762494bd1f61ab673487ae9b0fce8a107c7"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.6,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/3 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 1 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-23T21:20:01.291Z","repository_id":57651651,"created_at":"2025-08-23T21:20:01.291Z","updated_at":"2025-08-23T21:20:01.291Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28808325,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-27T07:14:39.408Z","status":"ssl_error","status_checked_at":"2026-01-27T07:14:39.098Z","response_time":168,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-27T07:38:05.492Z","updated_at":"2026-01-27T07:38:08.907Z","avatar_url":"https://github.com/stackus.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# dotenv\n\nYet another Go port of [dotenv](https://github.com/bkeepers/dotenv) environment variable dot-file library.\n\n## Installation\n\n```shell\ngo get github.com/stackus/dotenv\n```\n\n## Usage\n\nAdd your application configuration to your `.env` file in the root of your project:\n\n```shell\nS3_BUCKET=YOURS3BUCKET\nSECRET_KEY=YOURSECRETKEYGOESHERE\n```\n\n### Load()\n\nUse `Load()` to inject the variables read from the files into the current processes environment variables.\n\nLoad the variables in Go like the following:\n\n```go\npackage main\n\nimport (\n\t\"fmt\"\n\t\"os\"\n\t\n\t\"github.com/stackus/dotenv\"\n)\n\nfunc main() {\n    if err := dotenv.Load(); err != nil {\n        fmt.Fprintf(os.Stderr, \"error starting application: %s\", err)\n        os.Exit(1)\n    }\n\t\n    s3Bucket := os.Getenv(\"S3_BUCKET\")\n    secretKey := os.Getenv(\"SECRET_KEY\")\n\t\n    // ...\n}\n```\n\n### Parse()\n\nIf you do not want to alter the environment variables you can use `Parse()` to return all of the values read from the file as a `map[string]string`.\n\n```go\n// ...\n\nvalues, err := dotenv.Parse()\n\ns3Bucket := values[\"S3_BUCKET\"]\n\n// ...\n```\n\n### Defaults\n| Setting | Default | Purpose                                                               |\n| --- | --- |-----------------------------------------------------------------------|\n| Files  | .env | Names of the files that should be parsed for values                   |\n| Paths | . | Paths that should be searched for files                               |\n| Overload | false | Replace existing environment variables with values read in from files |\n| RequireAllFiles | false | Silently skip any files that could not be found and read              |\n| RequiredKeys | [] | List of keys that must exist in the environment                       |\n### Options\n\nBoth `Load()` and `Parse()` accept options that will alter how they work.\n\n#### Files(...string)\nProvide a list of file names to read values from.\n\n#### Paths(...string)\nProvide a list of paths to search for files with values.\n\n#### Overload()\n\u003e This is a `Load()` only option.\n\nReplace any existing values that either were already set in the environment variables or were set from a previously read file.\n\n#### RequiredKeys(...string)\n\u003e This is a `Load()` only option.\n\nProvides a list of keys that will be checked just before `Load()` is done. If any of the keys are not set in the environment then `Load()` will return an error message listing all missing keys.\n\n#### AllFilesRequired()\nThis will cause either `Load()` or `Parse()` to return an error when the first missing file is encountered.\n\n#### EnvironmentFiles(string)\nSets a group of files using the given environment name.\n\n| environment | Result                                                           |\n| --- |------------------------------------------------------------------|\n| test | .env.test.local, .env.test, .env                                 |\n| anything else | .env.\\\u003cenvironment\u003e.local, .env.local, .env.\\\u003cenvironment\u003e, .env |\n\n#### Using Options\n\nYou can pass in any combination of options you need to either `Load()` or `Parse()`.\n\n```go\n\nerr := dotenv.Load(\n        dotenv.EnvironmentFiles(os.Getenv(\"MY_APP_ENV\")),\n        dotenv.RequireKeys(\"DATABASE_URL\", \"HOST\", \"LOG_LEVEL\"),\n    )\n\n// the same goes for Parse()\n```\n\n## Autoload\nThere is an autoload as well if you do not need to make use of any of the options.\n\n```go\npackage main\n\nimport (\n\t_ \"github.com/stackus/dotenv/autoload\"\n)\n\nfunc main() {\n    // values have already been loaded\n}\n\n```\n\n## CLI\nYou can also use this library in the CLI to execute applications with modified environments.\n\n### Installation\n\n```shell\ngo install github.com/stackus/dotenv/cmd/dotenv@latest\n```\n\n### Usage\nPrefix the command with a call to dotenv first along with some arguments to load the file or files you need, such as:\n\n```shell\ndotenv -f .env -f .other-env -- your-command -a your-args\n```\n\nIn the above example `dotenv` was used to load values into the environment from two different files, then the command `your-command` and its arguments followed a split, identified as `--`. \n\nUse `--` to signal when the `dotenv` flag parser should stop. Everything to the right of it will be left unparsed and used as the command that will be run along with any arguments that may also exist.\n\nThe `dotenv` command will also accept the `-e` flag to set the environment which works like the `EnvironmentFiles(env)` option above, as well as the `-p` flag to provide one or more paths. `-p` may be repeated just like `-f`.\n\n### Similarities with the Ruby version\n\nNearly everything the Ruby version would parse is parsed in this version. With one major difference. There is no command substitution.\n\n```env\n# start simple and go from there\nFOO=bar             # bar\nFOO1=bar#baz        # bar#baz\nFOO2=fizz buzz      # fizz buzz\nFOO3=\"bar\"          # bar\nFOO4= \"bar\"         # bar\nFOO5 = \"bar\"        # bar\nFOO6=\"foo$FOO5\"     # foobar\nFOO7=\"foo\\$FOO5\"    # foo$FOO5\nFOO8=\"a multi\nline value\"         # a multi\\nline value\nBAR1='foo'          # foo\nBAR2='bar$BAR1'     # bar$BAR1\nBAR3: yaml-like     # yaml-like\nexport BAR4=bar     # bar\nexport UNDEFINED    # this will return a warning error just as the Ruby version does\n```\n\n\u003e It also doesn't parse `\"FOO=foo\\rBAR=bar\"` (strings that use only a carriage return) correctly.\n\n## Contributing\n\n1. Fork it\n2. Create your feature branch (`git checkout -b my-new-feature`)\n3. Commit your changes (`git commit -am 'Added some feature'`)\n4. Push to the branch (`git push origin my-new-feature`)\n5. Create new Pull Request\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstackus%2Fdotenv","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fstackus%2Fdotenv","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstackus%2Fdotenv/lists"}