@lowdep/env-diff
v1.0.0
Published
Compare two .env files for missing, extra, and changed keys — secret-safe redaction, CI-friendly, zero dependencies
Maintainers
Readme
env-diff
Compare two .env files for missing, extra, and changed keys. Automatically redacts secret-looking values (anything matching SECRET, PASSWORD, TOKEN, KEY, PRIVATE, etc.). Zero dependencies.
Useful for:
- Keeping
.env.examplein sync with team members'.envfiles - Comparing
.env.stagingvs.env.prod - CI checks that fail when required env vars are missing
Install
npm install -g env-diffOr without installing:
npx env-diff .env.example .envUsage
env-diff .env.example .env
env-diff .env.prod .env.staging --label-a prod --label-b staging
env-diff .env.example .env --strict # CI: fail if .env missing keys
env-diff a.env b.env --json # JSON output
env-diff a.env b.env --keys-only # Just keys, no valuesExample Output
env-diff .env.example → .env
-2 +1 ~1 =5
Missing in .env (2)
- SENTRY_DSN = https://abc...xy
- REDIS_URL = redis://localhost:6379
Extra in .env (1)
+ LOCAL_DEBUG = true
Changed (1)
~ DATABASE_URL
- postg***xx
+ postg***yy
5 key(s) identical: NODE_ENV, PORT, JWT_SECRET, LOG_LEVEL, API_BASESecret Redaction
By default, values for keys matching SECRET, PASSWORD, TOKEN, KEY, PRIVATE, CREDENTIAL, DSN, or API are redacted (e.g. abc***xy) — so you can paste output in tickets, share screenshots, or commit logs without leaking real secrets.
--show-values— still redact secrets, but show non-secret values--no-redact— DANGEROUS — show full plain-text values
CI Integration
# Fail the build if .env.example has been updated but .env hasn't
- name: Check env vars
run: npx env-diff .env.example .env --strict --keys-onlyExit code is 1 (in --strict mode) if any keys are missing or extra.
Options
| Flag | Description |
|---|---|
| --label-a <name> | Display label for the first file |
| --label-b <name> | Display label for the second file |
| --show-values | Show all non-secret values |
| --no-redact | Show full secret values (dangerous) |
| --strict | Exit 1 if any missing/extra keys |
| --keys-only | One-line-per-key output |
| --json | Machine-readable JSON |
| --quiet | Suppress "identical" summary |
License
MIT
Keywords
compare env files · dotenv diff · env comparison · .env diff · diff env · env sync · env example · secret redaction · zero dependencies · cli
Built to solve, shared to help — Rushabh Shah 🛠️✨
One of 40+ zero-dependency developer CLI tools — no node_modules, ever.
