Skip to content

chore(deps): bump dotenv from 16.6.1 to 18.0.4 - #344

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-18.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-18.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps dotenv from 16.6.1 to 18.0.4.

Changelog

Sourced from dotenv's changelog.

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv

faster than Node native parseEnv!

Changed

  • Injecting message sent to stderr rather than stdout and tips removed (#1037)

... (truncated)

Commits

Summary by CodeRabbit

  • Chores
    • Updated underlying project configuration. This change does not add or alter any user-facing features or functionality. No changes to the app’s visible experience are included in this release.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cattr-app/server-application/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a3cadb0b-a6e2-4734-a8be-9abbd8f9e4dc

📥 Commits

Reviewing files that changed from the base of the PR and between bf8cb5e and f914efa.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The pull request changes the dotenv dependency constraint in package.json from ^16.4.2 to ^18.0.4.

Changes

Dependency Update

Layer / File(s) Summary
Update dotenv version
package.json
The declared dotenv dependency constraint changes from ^16.4.2 to ^18.0.4.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: vermorag

Merge Risk: ⚪ Minimal · up to f914e

The dependency update has no established merge-blocking issue and is mergeable subject to normal installation and test checks.

Architecture Summary

Architecture risk: 🔵 Low · up to f914e

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: The dotenv dependency constraint changed from ^16.4.2 to ^18.0.4.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating the dotenv dependency from version 16.6.1 to 18.0.4.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

package.json

Parsing error: Missing semicolon. (2:8)


Comment @coderabbitai help to get the list of available commands.

@cattr-cla-bot

cattr-cla-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown

Contributor License Agreement

✅ CLA acceptance is not required for this pull request.

Exempt automation:

  • 🤖 dependabot[bot]

coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 21, 2026
Bumps [dotenv](https://github.com/motdotla/dotenv) from 16.6.1 to 18.0.4.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.6.1...v18.0.4)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump dotenv from 16.6.1 to 18.0.0 chore(deps): bump dotenv from 16.6.1 to 18.0.4 Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dotenv-18.0.0 branch from bf8cb5e to f914efa Compare September 30, 2026 22:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Development

Successfully merging this pull request may close these issues.

0 participants