Skip to main content

build status PyPI version

clean-dotenv

Automatically creates an .env.example which creates the same keys as your .env file, but without the values

Why?

There are projects which make use of an .env file. An .env file contains environment variables which are used during runtime, such as API keys. A typical .env file might look like this:

OPENAI_KEY="12345"
S3_BUCKET_NAME="testbucket"

An .env file should not be commited into a repo, since it can contain sensitive information1 (you should probably adding the .env file into your .gitignore). However, one needs to know which variables can be set in the .env file and as a result, a lot of projects (such as laravel), provide an .env.example file which is a template file. So you would copy the .env.template, rename it to .env and fill in the environment variables.

However, there is one issue with this approach: If one introduces a new environment variable, they need to remember to add it to the .env.example file. Unfortunately, if they forget this, it will not be noticed, since the program is using the .env file and not the .env.example. This pre-commit hook tries to mitigate this problem by creating an .env.example file automatically (based on your .env file), so the example .env file would become the following .env.example:

OPENAI_KEY=""
S3_BUCKET_NAME=""

Installation

pip install clean-dotenv

Console scripts

Consult clean-dotenv --help for the full set of options.

Common options:

  • --root_path: Defines the root path in which to look for .env files. This is not recursive
  • --keep value1 value2: Defines which values shall be kept in the .env file. In this example, every variable except for value1 and value2 would be cleaned.

As a pre-commit hook

See pre-commit for instructions

Sample .pre-commit-config.yaml

-   repo: https://github.com/hija/clean-dotenv
    rev: v0.0.7
    hooks:
    -   id: clean-dotenv

What does it do?

The tool looks for .env files in all directories and creates a new, corresponding filename .env.example which is save to commit, since it contains all the keys from your .env file, but without its values.

As a result, you always have an up-to-date .env.example file. This shall help to reduce forgetting updating the .env.example files!

Technical Background

Since a .env file is probably in the .gitignore file, we cannot rely on pre-commits files-filter. Instead, we tell pre-commit to run always. We then check for each subdirectory if an .env file exists. If it exists, we automatically create an .env.example file.

Alternatives

The biggest alternative is to not use .env files at all2. If you want to keep using .env files without using clean-dotenv you can use language specific tools, such as dotenv-safe for node.

Next Steps / Ideas

  • Add an option to specify the glob pattern to increase the performance (e.g. you could specify to look for dev/local.env only)
  1. https://www.zdnet.com/article/botnets-have-been-silently-mass-scanning-the-internet-for-unsecured-env-files/ ↩

  2. https://dev.to/gregorygaines/stop-using-env-files-now-kp0 ↩

Metadata

Release files for clean-dotenv 0.0.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for clean-dotenv 0.0.7
File Size Uploaded
clean_dotenv-0.0.7.tar.gz 7.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for clean-dotenv 0.0.7
File Interpreter ABI Platform
clean_dotenv-0.0.7-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 15.5 kB

Release files / clean_dotenv-0.0.7.tar.gz

Download URL clean_dotenv-0.0.7.tar.gz
Size 7.4 kB
Tags Source
SHA-256 checksum
How to use checksums
5f37d1fa68fb17ee569a7b3a36d7bf04397807ece44959682afbb9f265a5fbe6
BLAKE2b-256 checksum
How to use checksums
678118b856af7427b304bf8ccc5c1dba4686ea407a84e08569432838dee62ac7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.10.13

Release files / clean_dotenv-0.0.7-py2.py3-none-any.whl

Download URL clean_dotenv-0.0.7-py2.py3-none-any.whl
Size 8.1 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
db9efcc64b477f231e2548ac423d3b56d72eac47bf8d7fb41cb2f49d3f79fe3c
BLAKE2b-256 checksum
How to use checksums
be9ac6b81de650b9f23bdc5b211b1f5aff603dc160fee11914ecf5a95772dde9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.10.13

Release history Release notifications | RSS feed

This release

0.0.7 This release

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page