npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@kindgi/secrets-dotenv

v0.1.6

Published

Dev-mode `SecretBinding` over the project's own env files (`.env`, then `.env.local`, or `dev.envFiles`) — the same files, parsed the same way, as the app beside the pack — and Kindgi's own `.kindgi/secrets.env`, read last and written, plus the one defini

Readme

@kindgi/secrets-dotenv

The dev-mode SecretBinding — secrets for kindgi dev, straight from the project's env files — plus the one definition of which env files belong to a pack environment.

Not for production: plaintext on disk, no audit events, no versioning. Deployed environments use a durable, encrypted SecretBinding or an external secrets provider.

Which files

| Environment | Files read (lowest precedence first) | Writes go to | |---|---|---| | local (kindgi dev) | .env, .env.local — or dev.envFiles from kindgi.config.ts — then .kindgi/secrets.env | .kindgi/secrets.env (with appEnvFile: the app's last file, .env.local) | | anything else | .env.<envName> | the same file |

Paths are relative to the pack root. For local these are the same files, parsed the same way (@kindgi/dotenv-file: dotenv grammar, ${VAR} expansion), as the application beside the pack — Kindgi embedded in a Next.js app sees exactly what next dev sees. A key already in the app's .env is available to the pack without copying it anywhere. Kindgi's own file comes last, so it wins, and it's where a secret is written: a file the app doesn't load (a framework loads .env.local into every route). copyToKindgiFile gives Kindgi its own copy of names the app's files hold, and never edits them.

import { readPackEnv, resolvePackEnvFiles } from '@kindgi/secrets-dotenv';

resolvePackEnvFiles({ packDir, envName: 'local' });
// → { read: ['<pack>/.env', '<pack>/.env.local', '<pack>/.kindgi/secrets.env'],
//     write: '<pack>/.kindgi/secrets.env', app: [...the first two], appWrite: '<pack>/.env.local', … }

const env = await readPackEnv({ packDir, envName: 'local', env: process.env });
env.values; // merged + expanded; env.origin says which file supplied each name

Runtime config vs. the pack's secrets

One file can hold both. The KINDGI_ prefix is the line (isRuntimeKey, runtimeValues, packValues):

  • KINDGI_* — Kindgi's own runtime config (KINDGI_DATABASE_URL, …). Never visible through the binding, never written by it.
  • everything else — the pack's. An app's own DATABASE_URL is just a name the pack could reference; it never configures Kindgi.

The binding

import { createDotenvSecretBinding } from '@kindgi/secrets-dotenv';

const binding = createDotenvSecretBinding({
  packDir,
  localEnvFiles: ['.env', '.env.local'], // optional — dev.envFiles
  env: process.env, // optional — fallback for ${VAR} no file defines
});
  • Reads (list, get, resolve, getVersion, listVersions): the merged, expanded view without KINDGI_*. Versions are synthetic (versionId: 1).
  • set: setKey on the write target — one line changes, every other byte stays; atomic write, mode 0600. create-new reports already-exists if ANY of the files defines the name. Refuses KINDGI_*, the reserved kindgi. prefix, non-POSIX names, and values no dotenv quoting can hold.
  • rotate / revoke: unsupported — the error names the files to edit.
  • Scope-blind: dotenv files are flat; Scope is ignored.
  • ${VAR}: resolved across the files; env only fills names no file defines and never overrides a file's value. Nothing reads process.env unless you pass it.