Skip to content

chore(deps): bump dotenv from 16.4.5 to 17.3.1#7733

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/dotenv-17.3.1
Closed

chore(deps): bump dotenv from 16.4.5 to 17.3.1#7733
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/npm_and_yarn/dotenv-17.3.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 27, 2026

Bumps dotenv from 16.4.5 to 17.3.1.

Changelog

Sourced from dotenv's changelog.

17.3.1 (2026-02-12)

Changed

  • Fix as2 example command in README and update spanish README

17.3.0 (2026-02-12)

Added

  • Add a new README section on dotenv’s approach to the agentic future.

Changed

  • Rewrite README to get humans started more quickly with less noise while simultaneously making more accessible for llms and agents to go deeper into details.

17.2.4 (2026-02-05)

Changed

  • Make DotenvPopulateInput accept NodeJS.ProcessEnv type (#915)
  • Give back to dotenv by checking out my newest project vestauth. It is auth for agents. Thank you for using my software.

17.2.3 (2025-09-29)

Changed

  • Fixed typescript error definition (#912)

17.2.2 (2025-09-02)

Added

  • 🙏 A big thank you to new sponsor Tuple.app - the premier screen sharing app for developers on macOS and Windows. Go check them out. It's wonderful and generous of them to give back to open source by sponsoring dotenv. Give them some love back.

17.2.1 (2025-07-24)

Changed

  • Fix clickable tip links by removing parentheses (#897)

17.2.0 (2025-07-09)

Added

  • Optionally specify DOTENV_CONFIG_QUIET=true in your environment or .env file to quiet the runtime log (#889)
  • Just like dotenv any DOTENV_CONFIG_ environment variables take precedence over any code set options like ({quiet: false})
# .env
</tr></table> 

... (truncated)

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Mar 27, 2026
@monkeytypegeorge monkeytypegeorge added backend Server stuff packages Changes in local packages labels Mar 27, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch 2 times, most recently from 3b9ea71 to 67770c1 Compare March 30, 2026 14:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch from 67770c1 to 1d0af3a Compare April 7, 2026 09:41
@socket-security
Copy link
Copy Markdown

socket-security bot commented Apr 7, 2026

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch 2 times, most recently from 8fd4406 to 2c87b6c Compare April 7, 2026 11:16
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 7, 2026

Continuous integration check(s) failed. Please review the failing check's logs and make the necessary changes.

@github-actions github-actions bot added the waiting for update Pull requests or issues that require changes/comments before continuing label Apr 7, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch from 2c87b6c to 6c2e53e Compare April 7, 2026 11:20
@github-actions github-actions bot removed the waiting for update Pull requests or issues that require changes/comments before continuing label Apr 7, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch from 6c2e53e to 6f2f17d Compare April 7, 2026 11:22
Bumps [dotenv](https://github.com/motdotla/dotenv) from 16.4.5 to 17.3.1.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.4.5...v17.3.1)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 17.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/dotenv-17.3.1 branch from 6f2f17d to d650937 Compare April 7, 2026 11:24
@Miodec Miodec closed this Apr 7, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Apr 7, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/dotenv-17.3.1 branch April 7, 2026 11:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Server stuff dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code packages Changes in local packages

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants