🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 2 Min Lesezeit
0

I built a 1-file CLI to catch .env drift before it causes production bugs

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

Almost every developer has fought .env issues. They're silent, annoying, and they only show up after you deploy or after someone clones the repo.



Here's the exact failure I hit one too many times:




  1. I add STRIPE_KEY to my local .env.

  2. I ship code that reads process.env.STRIPE_KEY.

  3. I forget to add STRIPE_KEY to the committed .env.example.

  4. A teammate clones, runs the app, and it crashes on a missing variable.



The reverse is just as common: .env.example promises a key you never actually set locally — a silent misconfig waiting to bite.



The two files are supposed to declare the same set of keys. They drift apart constantly. So I built a small guardrail.






dotdrift



Zero dependencies, one command:




CODE
npx dotdrift









CODE
x drift detected between .env and .env.example

Missing in .env.example (add these so teammates know they're needed):
+ STRIPE_KEY

Tip: run "dotdrift sync" to update .env.example automatically.






It exits non-zero on drift, so it drops straight into CI:




CODE
- run: npx dotdrift --strict   # --strict also flags empty values









The part I actually wanted: sync



Detecting drift is half the problem. The annoying half is fixing the template by hand. So sync regenerates .env.example from your real .env:




CODE
npx dotdrift sync







  • values are stripped (KEY=),

  • your comments and blank-line grouping are preserved,

  • curated placeholders already in the template survive (a hand-written PORT=3000 stays),

  • it's idempotent — run it twice, nothing changes.



So updating the template is now one command instead of a manual chore.






Make it permanent






CODE
npx dotdrift hook






Installs a .git/hooks/pre-commit that blocks commits when things drift. A one-time tool becomes a continuous safety net.






Monorepo






CODE
npx dotdrift -r






Scans every subdirectory that has an .env/.env.example pair (skips node_modules, dist, etc.) and reports per service.






Notes




  • Zero dependencies — Node stdlib only, ~250 lines.

  • It only ever compares key names (and, with --strict, whether a value is empty). It never prints or transmits your secret values.

  • Understands KEY=value, export KEY=value, single/double quotes, KEY= (empty), # comments, and inline comments on unquoted values.

  • MIT licensed.



Repo: https://github.com/jjdoor/dotdrift

npm: npx dotdrift



If you hit a parsing edge case or the sync output isn't what you'd expect, open an issue — that's exactly the feedback I'm after.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I built a 1-file CLI to catch .env drift before it causes production bugs

Thematisch verwandte Begriffe: built, 1file, catch, drift · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...