We Are Forking dotenvy into dotenv-ng

The SecretSpec team has released dotenv-ng, a new Rust-based implementation for loading .env files, following a fork from the unmaintained dotenvy project. The fork was necessitated by a critical bug where the parser incorrectly interpreted secret values as variable substitutions, leading to authentication failures.
Why it matters
It highlights the risks of relying on unmaintained open-source dependencies for critical security infrastructure and the necessity of robust parsing in configuration management.
We have released dotenv-ng 1.0, a modern Rust implementation for loading and rendering .env files. It began as a fork of dotenvy after its parser changed a secret while reading it.
That may sound contradictory. SecretSpec is still on a mission to eliminate environment variables as a secrets interface , and we have written about where .env went wrong . It should not be the final home of a secret.
But migrating away from .env starts with reading it correctly.
Section titled “Why fork dotenvy?” The immediate failure was SecretSpec issue #73 . A dotenv file contained a value with bcrypt fragments:
TEST = "foo:$2a$10$TWoviNHS27HJMw1PKe4tBeIMlms6tWdYS9hKoHANKCQhluDlEt/gu" The file was intact. Reading it through the dotenv provider returned a different value because dotenvy treated the dollar-prefixed fragments as variable substitutions. The failure appeared later as an authentication error, not a parse error.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in