Vaar is an intelligent environment analysis toolkit for validating, understanding, and safely working with .env files across developer and agentic workflows.
It helps you catch broken .env files, misconfigurations in environments and helps you work with your secrets safely, be it development or production, for both humans and agents.
Issues with .env files are usually missed or overlooked during code review due to them being difficult to share and compare thanks to their sensitive nature. Since environment variables are not as easily reviewable as code artifacts, it is all the more important to ensure their hygiene and quality.
Vaar provides various tools to analyse your environment configuration safely. Each tool selects a safe scope, parses information from multiple sources, analyses it safely without leaking secrets, applies its own semantics and produces stable results.
Most dotenv linters are limited to .env files while secret scanners look for leaked credentials. Generic code-quality tools are not centered on environment correctness. Additionally, runtime validators only run after application code starts.
Vaar has begun with simple .env hygiene, but is envisioned to grow into a suite of repo-aware, intelligent environment correctness tooling.
Vaar currently provides:
- deterministic dotenv linting through
vaar lint - key-presence comparison between dotenv files through
vaar diff - stable text and JSON output for command-line users and automation
- safe, deterministic formatting fixes for supported lint findings
The roadmap extends this foundation toward repository-aware analysis across source code, contracts, infrastructure and external providers. Read the Roadmap for the planned direction.
go install github.com/envaar/vaar/cmd/vaar@latest
vaar --versionSource installs use the Go version declared in go.mod.
Release binaries are published for Linux, macOS and Windows on amd64 and arm64.
| Platform | Archives |
|---|---|
| Linux | vaar_linux_amd64.tar.gz, vaar_linux_arm64.tar.gz |
| macOS | vaar_darwin_amd64.tar.gz, vaar_darwin_arm64.tar.gz |
| Windows | vaar_windows_amd64.zip, vaar_windows_arm64.zip |
Download the matching archive and vaar_checksums.txt, then verify the archive, extract it and confirm the binary.
Note
The release workflow mandatorily publishes vaar_checksums.txt with SHA256 checksums for every release archive.
For Unix-like systems:
archive=vaar_linux_amd64.tar.gz
curl -LO "https://github.com/envaar/vaar/releases/latest/download/$archive"
curl -LO https://github.com/envaar/vaar/releases/latest/download/vaar_checksums.txt
grep "$archive" vaar_checksums.txt | sha256sum -c -
tar -xzf "$archive"
./vaar --versionFor macOS systems:
archive=vaar_linux_amd64.tar.gz
curl -LO "https://github.com/envaar/vaar/releases/latest/download/$archive"
curl -LO https://github.com/envaar/vaar/releases/latest/download/vaar_checksums.txt
grep "$archive" vaar_checksums.txt | shasum -a 256 -c -
tar -xzf "$archive"
./vaar --versionFor Windows PowerShell:
$archive = 'vaar_windows_amd64.zip'
Invoke-WebRequest -Uri "https://github.com/envaar/vaar/releases/latest/download/$archive" -OutFile $archive
Invoke-WebRequest -Uri "https://github.com/envaar/vaar/releases/latest/download/vaar_checksums.txt" -OutFile vaar_checksums.txt
$line = Select-String -Path .\vaar_checksums.txt -Pattern $archive
$expected = ($line.Line -split '\s+')[0].ToLower()
$actual = (Get-FileHash .\$archive -Algorithm SHA256).Hash.ToLower()
if ($actual -ne $expected) { throw "checksum mismatch" }
Expand-Archive .\$archive -DestinationPath .
.\vaar.exe --versionVaar has command-specific guides for detailed flags, output formats and exit codes. The examples below are simplified for an easy quick start.
To test out the linter's capabilities, run Vaar from the repository you want to check:
vaar lintSee the Lint guide for rule selection, JSON output, safe fixes, explicit targets, exit codes and the rule catalog. The basic example and broken example show representative lint input.
Compare the keys declared/present in two dotenv files:
vaar diff .env .env.exampleDiff compares key presence only and never compares or prints dotenv values. See the Diff guide for JSON output, quiet mode, exit codes and CI usage.
Use the command map to find the supported commands and their detailed references:
- Lint guide, including the rule catalog
- Diff guide
- Help guide and command-specific help references
- Developer primer for a practical codebase tour
Vaar's intends to become the one stop solution for all things related to environment variables.
vaar lintchecks dotenv syntax and deterministic formatting rules, with safe fixes where the result is unambiguous.vaar diffcompares key presence between two dotenv documents without exposing their values.
- source-code usage and repository structure
- contracts and schemas
- Docker, CI and framework configuration
- optional external providers and cloud state
vaar queryfor inspecting supported environment facts and status- broader lint rules that use repository context and explicit contracts
- richer diff comparisons across supported sources and scopes
- machine-readable integrations such as SARIF and CI annotations
Note
These goals are not set in stone and are subject to change. To propose a change in direction or scope, contact core@envaar.dev or open a Discussion.
Vaar is intentionally focused on environment and configurational correctness across complex use cases. It is not trying to be:
- simple environment syncing across teams without detailed features such as repository context, code usage or drift analysis.
- a tool that treats
.envfiles as the only source of truth instead of comparing them with example files, source code and config state. - runtime-only validation that waits for the application to start instead of analyzing the repo first.
- a generic configuration platform for arbitrary file formats rather than environment-variable correctness.
- a secret manager or vault replacement.
- a guessy scanner that reports weak patterns without clear evidence or reviewable context.
- a deployment or infrastructure orchestration tool that goes beyond environment correctness.
Those boundaries are intentional. Vaar should stay focused before it grows broader.
Note
These non-goals are not set in stone and are subject to change. If you wish to request to add or reconsider (remove) a non-goal or some new direction/scope that the team should explore, please reach out by sending a mail to core@envaar.dev or open a Discussion.
| Area | Current Support as of Latest Release |
|---|---|
| Operating systems | Linux, macOS, Windows |
| Architectures | amd64, arm64 |
| Shell completions | Bash, Zsh, Fish, PowerShell |
| Official install paths | go install, GitHub Release binaries |
| Go toolchain | Go version declared in go.mod |
Note
The scope of "Supported" means that the project expects installation, checksum verification and described vaar functionality to work for the above configurations. To request a new configuration, please create a new Issue
Vaar's documentation is being moved to vaar.envaar.dev/docs, where command usage and other reference material will be organized.
The documentation at /docs is the developer and maintainer documentation:
Please read System Overview to learn about the Repository Layout, Design Principles and other useful information.
Please read Development Workflow to understand the typical development steps for Vaar.
- If lint reports nothing, Vaar scanned the selected scope and found no remaining findings. Confirm you are in the repository/root you meant to scan.
- If diff reports no key differences, both dotenv files contain the same declared key set. Values are not compared.
- To verify a downloaded binary, compare it against
vaar_checksums.txtand then runvaar --versionafter extraction.
Please read CONTRIBUTING.md before opening a pull request.
Please read SECURITY.md before reporting a vulnerability or a redaction concern.
Vaar is licensed under the Apache License 2.0. See LICENSE.
To contact the maintainers of this project, please reach out by sending a mail to core@envaar.dev.
