Skip to content

feat: Replaced process.env vars with env-var - #3098

Open
ryan-yu-ibm wants to merge 7 commits into
mainfrom
fix/adding-env-var
Open

ryan-yu-ibm wants to merge 7 commits into
mainfrom
fix/adding-env-var

Conversation

@ryan-yu-ibm

@ryan-yu-ibm ryan-yu-ibm commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

🔗 Relevant links

🗒️ What

This PR reinforces our conditional checks made throughout dev-portal when involving environment variables. An instance of this would be the string 'true' versus the boolean true. It is very easy to switch between the two and could unintentionally change our dev environment.

🤷 Why

Future proofing our configs and functions that does environmental variable comparisons.

Note

I chose to not replace every process.env variable out with env-var since I interpreted the task as patching the areas that could be potential points of failures (i.e. places with conditional checks). Though, if desired, I can revamp all process.env variables to use env-var.

🛠️ How

  1. Installed env-var with npm; Looked into env-var documentation
  2. Replaced process.var.VERCEL_ENV to the env-var equivalent within next.config.js to test functionality
  3. Queried Bob to comb through repo for instances of process.env that do a direct comparison
  4. Provided example of how to change those instances and had it revise with me before applying any changes
  5. Made sure the local build still started after env changes

📸 Design Screenshots

🧪 Testing

  1. Open the preview and make sure the site still functions
  2. Note if anything breaks or is off

💭 Anything else?

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

@vercel

vercel Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
dev-portal Ready Ready Preview Oct 10, 2026 5:26pm UTC

Request Review

@ryan-yu-ibm
ryan-yu-ibm requested review from a team and williamdalessandro and removed request for a team September 8, 2026 23:10
@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

📦 Next.js Bundle Analysis

This analysis was generated by the next.js bundle analysis action 🤖

⚠️ Global Bundle Size Increased

Page Size (compressed)
global 349.67 KB (🟡 +9.86 KB)
Details

The global bundle is the javascript bundle that loads alongside every page. It is in its own category because its impact is much higher - an increase to its size means that every page on your website loads slower, and a decrease means every page loads faster.

Any third party scripts you have added directly to your app using the <script> tag are not accounted for in this analysis

If you want further insight into what is behind the changes, give @next/bundle-analyzer a try!

@ryan-yu-ibm ryan-yu-ibm changed the title Fix: Replaced process.env vars with env-var feat: Replaced process.env vars with env-var Sep 9, 2026

@williamdalessandro williamdalessandro left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @ryan-yu-ibm good job on this so far! I agree with not replacing the use of process.env everywhere and found an edge case with env-var and next.js's webpack bundler that I detailed below.

At first I wasn't really sure if we really wanted to use env-var just because it adds another package to the project and it hasn't been updated in 2 years. However after looking into it, it is extremely lightweight and doesn't add any runtime dependencies so I don't mind it hanging around in that case

Comment thread src/pages/_app.tsx Outdated
Comment thread src/pages/_app.tsx Outdated
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

This PR is stale because it has been open 20 days with no activity. It will be closed in 5 days unless you remove the stale label or comment.

@hivecommons-hive

Copy link
Copy Markdown
ec75212

⚠️ Sentinel alert — maintainer review required

Hive flagged this PR (author @ryan-yu-ibm, head ec75212c3d57) because it matches behaviors that can override security controls, escalate privileges or damage the codebase. This is a heuristic, not an accusation — a maintainer should confirm the change is intended before it merges.

  • sensitive_path — changes 2 sensitive path(s) (Touches a sensitive path (OWNERS, workflows, policies, hive config, security docs, …))
    • package-lock.json
    • package.json

Hive added the sentinel-alert label. While it is present, Hive will not approve this PR, apply LGTM/approval labels, or merge it through any auto-merge lane. Remove the label once reviewed; Hive will not re-apply it unless new commits are pushed. Tune paths and behaviors under sentinel in hive.yaml or the dashboard Security tab.

@hashicorp-cla-app

Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


1 out of 2 committers have signed the CLA.

  • ryan-yu-ibm
  • hivecommons-hive[bot]

Have you signed the CLA already but the status is still pending? Recheck it.

This branch was successfully deployed

1 active deployment
Preview — 6c1e82c6 Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants