Skip to content

dotenv_path_absent

Assert a JSONPath query over the document matches nothing; one file-level violation if present.

Semantics:

  • The query must select zero nodes. Any match fires exactly one violation for the file — never per-match, so a $[?…] filter that fans out over every top-level key still yields a single violation.
  • The existence sibling of the value-checking kinds; mirrors file_absent for a path. equals / matches / if_present don’t apply.
  • Useful for forbidding a key: a postinstall script in package.json, a [patch] table in Cargo.toml, or write-all permissions in a workflow.
OptionTypeRequiredDefaultDescription
pathstringyesJSONPath expression rooted at $. The rule fires one violation per file if the query matches any node (the path must be absent).

Plus the common paths, level, id, and when fields. This table is generated from the JSON Schema; option types and defaults are authoritative.

The rule fires on this repository:

.env
.env
NODE_ENV=production
AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMIexampleKEY

With this .alint.yml:

version: 1
rules:
- id: no-committed-secret
kind: dotenv_path_absent
paths: ".env"
path: "$.AWS_SECRET_ACCESS_KEY"
level: error
message: >-
A secret is committed in .env; move it to a secrets manager and keep
.env out of version control.

alint check reports:

Terminal window
--- .env -----------------------------------------------------------------------
x error no-committed-secret
A secret is committed in .env; move it to a secrets manager and
keep .env out of version control.
Summary (1 violation):
x 1 error
0 passing * 1 failing

This repository is compliant:

.env
.env
NODE_ENV=production
PORT=8080

With this .alint.yml:

version: 1
rules:
- id: no-committed-secret
kind: dotenv_path_absent
paths: ".env"
path: "$.AWS_SECRET_ACCESS_KEY"
level: error

alint check reports:

Terminal window
v All 1 rule(s) passed.