Skip to content

Bump dotenv from 17.4.2 to 18.0.4 in /api - #1019

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/api/dotenv-18.0.4
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/api/dotenv-18.0.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps dotenv from 17.4.2 to 18.0.4.

Changelog

Sourced from dotenv's changelog.

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv

faster than Node native parseEnv!

Changed

  • Injecting message sent to stderr rather than stdout and tips removed (#1037)

... (truncated)

Commits

@dependabot dependabot Bot added api API backend changes dependencies Dependency updates labels Sep 28, 2026

@sridharkalaibala sridharkalaibala left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the dotenv update and generated lockfile. The published API, database, desktop, lint, docs, packaging, secret-scan, and CodeQL checks are green.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/api/dotenv-18.0.4 branch from 0796e53 to 89f2f43 Compare September 29, 2026 13:15

@sridharkalaibala sridharkalaibala left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the refreshed dotenv update. The manifest and lockfile changes are limited to dotenv 18.0.4, whitespace checks pass, and all required CI and CodeQL checks are green.

Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.4.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.4)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/api/dotenv-18.0.4 branch from 89f2f43 to c262c7d Compare September 30, 2026 07:15

@sridharkalaibala sridharkalaibala left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the refreshed dotenv update. The manifest and generated lockfile changes remain scoped, whitespace checks pass, and all required CI and CodeQL checks are green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api API backend changes dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant