Skip to content

Latest commit

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

env-diff

Zero dependenciesNodeLicense: MITPlatform

Compare two .env files for missing, extra, and changed keys. Automatically redacts secret-looking values (anything matching SECRET, PASSWORD, TOKEN, KEY, PRIVATE, etc.). Zero dependencies.

Useful for:

  • Keeping .env.example in sync with team members' .env files
  • Comparing .env.staging vs .env.prod
  • CI checks that fail when required env vars are missing

Install

npm install -g env-diff

Or without installing:

npx env-diff .env.example .env

Usage

env-diff .env.example .env
env-diff .env.prod .env.staging --label-a prod --label-b staging
env-diff .env.example .env --strict # CI: fail if .env missing keys
env-diff a.env b.env --json # JSON output
env-diff a.env b.env --keys-only # Just keys, no values

Example Output

env-diff .env.example → .env
-2 +1 ~1 =5
Missing in .env (2)
- SENTRY_DSN = https://abc...xy
- REDIS_URL = redis://localhost:6379
Extra in .env (1)
+ LOCAL_DEBUG = true
Changed (1)
~ DATABASE_URL
- postg***xx
+ postg***yy
5 key(s) identical: NODE_ENV, PORT, JWT_SECRET, LOG_LEVEL, API_BASE

Secret Redaction

By default, values for keys matching SECRET, PASSWORD, TOKEN, KEY, PRIVATE, CREDENTIAL, DSN, or API are redacted (e.g. abc***xy) — so you can paste output in tickets, share screenshots, or commit logs without leaking real secrets.

  • --show-values — still redact secrets, but show non-secret values
  • --no-redactDANGEROUS — show full plain-text values

CI Integration

# Fail the build if .env.example has been updated but .env hasn't
- name: Check env varsrun: npx env-diff .env.example .env --strict --keys-only

Exit code is 1 (in --strict mode) if any keys are missing or extra.


Options

FlagDescription
--label-a <name>Display label for the first file
--label-b <name>Display label for the second file
--show-valuesShow all non-secret values
--no-redactShow full secret values (dangerous)
--strictExit 1 if any missing/extra keys
--keys-onlyOne-line-per-key output
--jsonMachine-readable JSON
--quietSuppress "identical" summary

License

MIT


Keywords

compare env files · dotenv diff · env comparison · .env diff · diff env · env sync · env example · secret redaction · zero dependencies · cli


Built to solve, shared to help — Rushabh Shah 🛠️✨

One of 40+ zero-dependency developer CLI tools — no node_modules, ever.

About

Compare two .env files for missing, extra, and changed keys — secret-safe redaction, CI-friendly, zero dependencies

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages