npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@envdiff/cli

v0.7.0

Published

Catch config drift in CI — fail a deploy if a required env var is missing or wrong.

Readme

envdiff

Catch config drift in CI — fail a deploy before it ships with a missing or wrong environment variable, instead of finding out from a crash report.

Free to compare two local files, or read a docker-compose.yml service's vars. Connecting to a live provider account (Vercel, Netlify, Heroku, or DigitalOcean, with more on the way) needs a one-time EnvDiff license — the same one that unlocks the web app.

Install

npm install -g @envdiff/cli

Or skip the install and use npx @envdiff/cli directly in a pipeline.

Quick start

Compare two local files — free, no license, no network call beyond reading the files:

envdiff check --local .env --against .env.production

Pull straight from Vercel instead:

envdiff license set ENVDIFF-XXXX-XXXX-XXXX-XXXX-XXXX-XXXX-XXXX-XXXX   # once, saves it to ~/.envdiff/config.json
envdiff check --local .env --vercel-project my-app --vercel-token $VERCEL_TOKEN

Or from Netlify:

envdiff check --local .env --netlify-site my-app --netlify-token $NETLIFY_TOKEN

Or from Heroku:

envdiff check --local .env --heroku-app my-app --heroku-token $HEROKU_TOKEN

Or from a DigitalOcean App Platform app (optionally merging in one component's own vars over the app-level ones):

envdiff check --local .env --do-app my-app --do-component web --do-token $DIGITALOCEAN_TOKEN

Or read a service's vars straight out of a docker-compose.yml — free, no license, no account, and it resolves any env_file: the service references relative to the compose file's own directory:

envdiff check --local .env --compose-file docker-compose.yml --compose-service web

Or check that a fixed list of keys exists, with nothing to compare against:

envdiff check --local .env --required DATABASE_URL,STRIPE_KEY,JWT_SECRET

In CI (GitHub Actions example)

- name: Check env vars before deploy
  run: npx @envdiff/cli check --local .env.example --vercel-project my-app
  env:
    VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN }}
    ENVDIFF_LICENSE: ${{ secrets.ENVDIFF_LICENSE }}

envdiff check exits 1 when drift is found (per --fail-on) and 0 when it's clean — that's what fails the pipeline step. It exits 2 for a setup problem (bad license, unreachable provider, missing file), so you can tell "your config is broken" apart from "the check itself couldn't run."

envdiff check

| Flag | Default | What it does | |---|---|---| | --local <path> | .env | The file to check | | --against <path> | — | Compare against another local file. Free, no license. | | --vercel-project <idOrName> | — | Pull the comparison side from a Vercel project. Requires a license. | | --vercel-env <target> | production | production, preview, or development | | --vercel-token <token> | $VERCEL_TOKEN | Vercel access token | | --netlify-site <idOrName> | — | Pull the comparison side from a Netlify site. Requires a license. | | --netlify-context <context> | production | production, deploy-preview, or dev | | --netlify-token <token> | $NETLIFY_TOKEN | Netlify personal access token | | --heroku-app <idOrName> | — | Pull the comparison side from a Heroku app's config vars. Requires a license. | | --heroku-token <token> | $HEROKU_TOKEN | Heroku API key | | --do-app <idOrName> | — | Pull the comparison side from a DigitalOcean App Platform app. Requires a license. | | --do-component <name> | — | Merge in one component's own vars over the app-level ones. Omit to use app-level vars only. | | --do-token <token> | $DIGITALOCEAN_TOKEN | DigitalOcean access token | | --compose-file <path> | — | Read the comparison side from a docker-compose.yml service. Free, no license. | | --compose-service <name> | — | Which service in --compose-file to read. Required alongside it. | | --license <key> | $ENVDIFF_LICENSE or the saved one | Required only when using --vercel-project, --netlify-site, --heroku-app, or --do-app | | --required <keys> | — | Comma-separated keys that must exist in --local. No second source needed. | | --fail-on <mode> | missing | missing, different, any, or none (report only, never fail) | | --api <url> | https://envdiff.dev | Override the API base — useful against a local dev Worker | | --json | — | Machine-readable output instead of a table |

envdiff license

envdiff license set <key>     # validate and save a license locally
envdiff license show          # print the saved key, masked
envdiff license remove        # clear it

The license is stored in ~/.envdiff/config.json (mode 0600). In CI, skip this and pass --license/ENVDIFF_LICENSE per-run instead — most CI runners are ephemeral, so there's nothing to persist between builds anyway.

Privacy

Only key names and statuses (match / different / missing) are ever printed or exported. Provider tokens go straight from your machine to the provider's own API — never through EnvDiff's servers. See envdiff.dev for the full privacy write-up.