{"_id":"@asdsadw12312dwd2112xz/env-encrypt-cli","name":"@asdsadw12312dwd2112xz/env-encrypt-cli","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@asdsadw12312dwd2112xz/env-encrypt-cli","version":"1.0.0","description":"Encrypt and decrypt .env file values for secure storage in git","type":"module","main":"dist/index.js","bin":{"env-encrypt-cli":"dist/index.js"},"scripts":{"build":"tsup","prepublishOnly":"npm run build"},"keywords":["env","encrypt","decrypt","dotenv","secrets","git"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/okirmio-create/env-encrypt-cli.git"},"dependencies":{"chalk":"^5.3.0","commander":"^12.1.0"},"devDependencies":{"@types/node":"^22.0.0","tsup":"^8.0.0","typescript":"^5.5.0"},"gitHead":"8d3182b2c4c98fce632697d5ec59a5a0eadf7583","_id":"@asdsadw12312dwd2112xz/env-encrypt-cli@1.0.0","bugs":{"url":"https://github.com/okirmio-create/env-encrypt-cli/issues"},"homepage":"https://github.com/okirmio-create/env-encrypt-cli#readme","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-3NR6fmm7o5AeIlqn8KY2T2y6o+zv5tO0p0xy92gOvR2fHUJbIZaIGgudqIpf46Zaqyw/Z1wkYp/hVLXjVsOD6A==","shasum":"ac434b98b716fcef73731adad0bb071ad3811158","tarball":"https://registry.npmjs.org/@asdsadw12312dwd2112xz/env-encrypt-cli/-/env-encrypt-cli-1.0.0.tgz","fileCount":6,"unpackedSize":21047,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCacz5loXwN2V5e01HO0eBaMHb47q3vh3uK1gj1XdJOzgIhAId/FbVfaaAmA13FH7EZvI4Dd8Lvag3Vc5W2lTkrMVcW"}]},"_npmUser":{"name":"asdsadw12312dwd2112xz","email":"okirmio@gmail.com"},"directories":{},"maintainers":[{"name":"asdsadw12312dwd2112xz","email":"okirmio@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/env-encrypt-cli_1.0.0_1775436276240_0.01563231614909677"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-06T00:44:36.173Z","1.0.0":"2026-04-06T00:44:36.383Z","modified":"2026-04-06T00:44:36.648Z"},"maintainers":[{"name":"asdsadw12312dwd2112xz","email":"okirmio@gmail.com"}],"description":"Encrypt and decrypt .env file values for secure storage in git","homepage":"https://github.com/okirmio-create/env-encrypt-cli#readme","keywords":["env","encrypt","decrypt","dotenv","secrets","git"],"repository":{"type":"git","url":"git+https://github.com/okirmio-create/env-encrypt-cli.git"},"bugs":{"url":"https://github.com/okirmio-create/env-encrypt-cli/issues"},"license":"MIT","readme":"# env-encrypt-cli\n\nEncrypt and decrypt `.env` file values for secure storage in git.\n\nValues are encrypted with AES-256-GCM while keys remain readable:\n\n```\nDB_HOST=enc:v1:base64data...\nDB_PORT=enc:v1:base64data...\n```\n\n## Install\n\n```bash\nnpm install -g env-encrypt-cli\n```\n\n## Usage\n\n### Encrypt\n\n```bash\n# Encrypt .env → .env.encrypted\nenv-encrypt-cli encrypt -k my-secret-key\n\n# Custom input/output\nenv-encrypt-cli encrypt -i .env.production -o .env.production.encrypted -k my-secret-key\n\n# Key from environment variable\nexport ENV_ENCRYPT_KEY=\"my-secret-key\"\nenv-encrypt-cli encrypt\n\n# Key from file\nenv-encrypt-cli encrypt --key-file ./secret.key\n```\n\n### Decrypt\n\n```bash\n# Decrypt .env.encrypted → .env\nenv-encrypt-cli decrypt -k my-secret-key\n\n# Custom input/output\nenv-encrypt-cli decrypt -i .env.production.encrypted -o .env.production -k my-secret-key\n```\n\n### Rotate Key\n\n```bash\n# Re-encrypt all values with a new key\nenv-encrypt-cli rotate -k old-key --new-key new-key\n```\n\n## Key Resolution\n\nKeys are resolved in this order:\n\n1. `--key-file <file>` — read key from a file\n2. `-k/--key <value>` — if the value matches `^[A-Z_][A-Z0-9_]*$`, it is treated as an environment variable name; otherwise used as a literal key\n3. `ENV_ENCRYPT_KEY` environment variable\n\n## Encrypted Format\n\nEach encrypted value uses the format:\n\n```\nenc:v1:<base64(salt + iv + authTag + ciphertext)>\n```\n\n- **Algorithm**: AES-256-GCM\n- **Key derivation**: scrypt (32-byte salt)\n- **IV**: 16 bytes, random per value\n- **Auth tag**: 16 bytes (GCM integrity)\n\n## Workflow\n\n1. Add `.env` to `.gitignore`\n2. Encrypt: `env-encrypt-cli encrypt -k $KEY`\n3. Commit `.env.encrypted`\n4. On deploy/checkout: `env-encrypt-cli decrypt -k $KEY`\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-e77333c20e749d279e3e6aff4f7f49a5"}