Problem
package.json:32 pins "dotenv": "^16.1.3" (resolved 16.6.1). Current published major on npm is 17.4.2 — one major ahead. Per the project's -r dotenv/config preload usage in src/index.ts/src/recommend.ts invocation (package.json index/recommend scripts), the relevant breaking change is in dotenv 17.0.0: quiet now defaults to false, so dotenv/config prints an informational [dotenv@17.x.x] injecting env (N) from .env line to stderr on every run instead of staying silent by default (confirmed via the project's own CHANGELOG.md, entry for 17.0.0, 2025-06-27: "Default quiet to false"). The .env.vault feature (unused here) was also removed in 17.0.0, and preload itself remains supported in 17.4.2 (only slated for removal in an unreleased future version), so -r dotenv/config continues to work unchanged.
Acceptance criteria
dotenv dependency in package.json is bumped to ^17.4.2, with package-lock.json updated accordingly.
- Given the new default startup log line, either accept it or explicitly preserve today's silent behavior by adding
DOTENV_CONFIG_QUIET=true to .env.example (with a short comment) — pick whichever the reviewer prefers, but the log-visibility change must be a deliberate choice, not an unnoticed side effect.
npm run index -- --help and npm run recommend -- --help still load environment variables correctly (verify getEnv-based checks in src/utils/env.ts still pass).
npm run lint, npm run typecheck, and npm test all pass.
Scope
Only the dotenv dependency version and, if chosen, the DOTENV_CONFIG_QUIET opt-in in .env.example. Do not touch other dependencies or the env-loading code in src/utils/env.ts.
Generated by GitHub Maintenance Audit · sonnet50 · 74.4 AIC · ⌖ 17.8 AIC · ⊞ 7.3K · ◷
Problem
package.json:32pins"dotenv": "^16.1.3"(resolved16.6.1). Current published major on npm is17.4.2— one major ahead. Per the project's-r dotenv/configpreload usage insrc/index.ts/src/recommend.tsinvocation (package.jsonindex/recommendscripts), the relevant breaking change is in dotenv17.0.0:quietnow defaults tofalse, sodotenv/configprints an informational[dotenv@17.x.x] injecting env (N) from .envline to stderr on every run instead of staying silent by default (confirmed via the project's ownCHANGELOG.md, entry for17.0.0, 2025-06-27: "Defaultquietto false"). The.env.vaultfeature (unused here) was also removed in17.0.0, and preload itself remains supported in17.4.2(only slated for removal in an unreleased future version), so-r dotenv/configcontinues to work unchanged.Acceptance criteria
dotenvdependency inpackage.jsonis bumped to^17.4.2, withpackage-lock.jsonupdated accordingly.DOTENV_CONFIG_QUIET=trueto.env.example(with a short comment) — pick whichever the reviewer prefers, but the log-visibility change must be a deliberate choice, not an unnoticed side effect.npm run index -- --helpandnpm run recommend -- --helpstill load environment variables correctly (verifygetEnv-based checks insrc/utils/env.tsstill pass).npm run lint,npm run typecheck, andnpm testall pass.Scope
Only the
dotenvdependency version and, if chosen, theDOTENV_CONFIG_QUIETopt-in in.env.example. Do not touch other dependencies or the env-loading code insrc/utils/env.ts.