npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

env-schema-tool

v1.0.0

Published

Validate, secure, document, audit, and manage environment variables with confidence.

Readme

🛡️ Env Sentinel (dotenv-schema)

Validate, secure, document, audit, and manage environment variables with confidence.

Env Sentinel is a complete environment variable toolkit for modern JavaScript and TypeScript applications. It ensures your application never starts with invalid configuration, warns you about leaked secrets, and generates beautiful documentation automatically.

✨ Features

  • Type-Safe Validation: Define your schema once and get fully typed env objects anywhere.
  • Fail Fast: Stops your application instantly if required variables are missing or invalid.
  • Security Audits: Detects hardcoded secrets in source code, weak passwords, and public leaks.
  • Automated Documentation: Generates .env.example and env.md directly from your schema.
  • Framework Adapters: First-class support for Next.js, Vite, Node, and more.

📦 Installation

npm install dotenv-schema

🚀 Getting Started

Create your environment schema in src/env.ts:

import { defineEnv } from 'dotenv-schema';

export const env = defineEnv({
  PORT: {
    type: 'number',
    default: 3000,
    description: 'The server port to bind to',
  },
  DATABASE_URL: {
    type: 'url',
    required: true,
    description: 'PostgreSQL connection string',
    secret: true,
  },
  JWT_SECRET: {
    type: 'string',
    required: true,
    minLength: 32,
    secret: true,
  }
});

Now use the typed env object anywhere in your app:

import { env } from './env';

console.log(`Starting server on port ${env.PORT}`);

🛠 CLI Usage

Env Sentinel comes with a powerful CLI (env-sentinel) to audit your environment setup:

Validate Setup

Check if the current environment matches the schema:

npx env-sentinel validate

Audit Configuration and Security

Scan all .env files and source code for missing variables, unused variables, and security leaks:

npx env-sentinel audit

Generate Documentation

Generate .env.example and markdown documentation:

npx env-sentinel generate --format example
npx env-sentinel generate --format markdown

🧱 Framework Integrations

Env Sentinel provides framework-specific adapters out of the box:

Next.js

import { defineNextEnv } from 'dotenv-schema/next';

export const env = defineNextEnv({ ... });

Vite

import { defineViteEnv } from 'dotenv-schema/vite';

export const env = defineViteEnv({ ... });

🔄 CI/CD Integration

You can easily integrate Env Sentinel into your GitHub Actions pipeline to prevent misconfigured environments from merging into production:

steps:
  - run: npm install
  - run: npx env-sentinel check

If check (which runs audit) detects missing variables or CRITICAL security flaws (like a hardcoded Stripe key), it will fail the build with exit code 1.

License

MIT