Skip to content

deps: bump dotenv from 16.6.1 to 17.4.2#101

Merged
Pyronewbic merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-17.4.2
May 19, 2026
Merged

deps: bump dotenv from 16.6.1 to 17.4.2#101
Pyronewbic merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dotenv-17.4.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 14, 2026

Copy link
Copy Markdown
Contributor

Bumps dotenv from 16.6.1 to 17.4.2.

Changelog

Sourced from dotenv's changelog.

17.4.2 (2026-04-12)

Changed

  • Improved skill files - tightened up details (#1009)

17.4.1 (2026-04-05)

Changed

  • Change text injecting to injected (#1005)

17.4.0 (2026-04-01)

Added

  • Add skills/ folder with focused agent skills: skills/dotenv/SKILL.md (core usage) and skills/dotenvx/SKILL.md (encryption, multiple environments, variable expansion) for AI coding agent discovery via the skills.sh ecosystem (npx skills add motdotla/dotenv)

Changed

  • Tighten up logs: ◇ injecting env (14) from .env (#1003)

17.3.1 (2026-02-12)

Changed

  • Fix as2 example command in README and update spanish README

17.3.0 (2026-02-12)

Added

  • Add a new README section on dotenv’s approach to the agentic future.

Changed

  • Rewrite README to get humans started more quickly with less noise while simultaneously making more accessible for llms and agents to go deeper into details.

17.2.4 (2026-02-05)

Changed

  • Make DotenvPopulateInput accept NodeJS.ProcessEnv type (#915)
  • Give back to dotenv by checking out my newest project vestauth. It is auth for agents. Thank you for using my software.

17.2.3 (2025-09-29)

Changed

  • Fixed typescript error definition (#912)

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github May 14, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

socket-security Bot commented May 14, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updateddotenv@​16.6.1 ⏵ 17.4.29910010092100

View full report

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/dotenv-17.4.2 branch from bc4dfb1 to 6c74d59 Compare May 14, 2026 19:31
Bumps [dotenv](https://github.com/motdotla/dotenv) from 16.6.1 to 17.4.2.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.6.1...v17.4.2)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 17.4.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/dotenv-17.4.2 branch from 6c74d59 to 63ff0b0 Compare May 17, 2026 08:09
@Pyronewbic Pyronewbic merged commit 250d218 into main May 19, 2026
9 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/dotenv-17.4.2 branch May 19, 2026 04:55
Pyronewbic pushed a commit that referenced this pull request May 19, 2026
Dependabot PRs #101 (dotenv 16→17) and #102 (axios-cookiejar-support 5→7)
updated yarn.lock but not package-lock.json. CI uses npm install, so every
run had to ad-hoc resolve these mismatches, causing non-deterministic behaviour
in the api job. Regenerated with npm install --package-lock-only.

https://claude.ai/code/session_01B8vFxRRcgDukfk2AQGbsgP
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant