Skip to main content

dotguard

Auto-generate documented .env.example files from your codebase.

Auto-generate documented .env.example files from your codebase.

Ever had a deploy fail because someone added os.getenv("NEW_VAR") but forgot .env.example? dotguard fixes that - automatically.

dotguard scans your codebase and automatically generates a fully documented .env.example - grouped, commented, and ready to commit.

Features

  • ⚡ Zero dependencies — pure Python (installs in ~1s)
  • 🌍 Language agnostic — Python, JS, TS, shell, YAML, TOML
  • 🧠 Smart grouping — auto-groups variables by prefix
  • 🔐 Secret detection — flags _KEY, _SECRET, _PASSWORD, _TOKEN
  • 🤖 CI-ready — --check fails if .env.example is outdated

Demo

dotguard in action

Install

pip install dotguard-scan

Usage

dotguard scan                    # scan current directory → .env.example
dotguard scan ./backend          # scan specific folder
dotguard scan --output prod.env  # custom output filename
dotguard scan --check            # CI mode: exit 1 if undocumented vars found
dotguard diff                    # compare .env vs .env.example, show missing keys
dotguard audit                   # show all vars, which files use them, flag secrets

Quick Demo

🔍 Scanning ./myproject...

  ✔ 23 files scanned
  ✔ 11 environment variables found
  ⚠  3 secrets detected (SECRET_KEY, DB_PASSWORD, AUTH_TOKEN)
  ✔ .env.example written

  Variables by group:
  DATABASE  ████  3 vars
  SMTP      ██    2 vars
  APP       ████  4 vars
  SECRETS   ███   3 vars  ⚠

Generated Output

dotguard produces a clean, grouped .env.example with comments showing where each variable is used:

# ─────────────────────────────────────
# SECRETS  ⚠️  Never commit real values
# ─────────────────────────────────────

# Used in: config.py:4
SECRET_KEY=your-secret-here

# Used in: auth.py:9
AUTH_TOKEN=your-secret-here


# ─────────────────────────────────────
# DATABASE
# ─────────────────────────────────────

# Used in: db.py:12, config.py:3
DATABASE_URL=postgresql://user:password@localhost:5432/dbname

# Used in: cache.py:8
REDIS_HOST=localhost


# ─────────────────────────────────────
# APP
# ─────────────────────────────────────

# Used in: settings.py:3
DEBUG=true

CI Integration

Add dotguard scan --check to your CI pipeline. It exits with code 1 if any environment variable in your code is missing from .env.example:

# GitHub Actions example
- name: Check env docs
  run: dotguard scan --check

Supported Patterns

Pattern Language
os.getenv("KEY") Python
os.environ["KEY"] Python
os.environ.get("KEY") Python
process.env.KEY JavaScript
$KEY / ${KEY} Shell
getenv("KEY") Generic

License

Licensed under The MIT License.

⭐ Support & Contributing

If you find this project useful, consider:

  • ⭐ Starring the repository
  • 👤 Following me for more projects
  • 🛠️ Contributing to improve the tool

Contributions are always welcome! Feel free to open issues or submit pull requests.

Metadata

Release files for dotguard-scan 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dotguard-scan 0.1.0
File Size Uploaded
dotguard_scan-0.1.0.tar.gz 10.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dotguard-scan 0.1.0
File Interpreter ABI Platform
dotguard_scan-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.3 kB

Release files / dotguard_scan-0.1.0.tar.gz

Download URL dotguard_scan-0.1.0.tar.gz
Size 10.1 kB
Tags Source
SHA-256 checksum
How to use checksums
c2c01f8aaf32cefd12d0094fdcf411dd6507f3b4cd91fe8e49682ab22533d530
BLAKE2b-256 checksum
How to use checksums
56294d43708aaa961b34f19b44b0482af29a49e4fcc0e1694f85062d16ec178b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.3

Release files / dotguard_scan-0.1.0-py3-none-any.whl

Download URL dotguard_scan-0.1.0-py3-none-any.whl
Size 10.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a9175417f33e7e9bc6c8e814398e888586952c6275116a325e8abeda392c4549
BLAKE2b-256 checksum
How to use checksums
c3fe465621d6e1172ab3ebaf9d5095fe2fd836242eb4356d5ba2a6c56d2c44a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.3

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page