Vite · Security

VITE0005Do not expose secrets through Vite define

Flags secret define in Vite define code before it leaks into runtime behavior.

Why it happens

Secrets that reach public runtime config or client bundles can be exposed to every visitor and crawler.

Fix

Remove secret define, or move it to the Vite runtime/API that owns that behavior.

Example

Keep secrets out of define

Before

export default defineConfig({
  define: {
    __API_SECRET__: JSON.stringify(process.env.API_SECRET),
  },
})

After

export default defineConfig({
  define: {
    __PUBLIC_VERSION__: JSON.stringify(process.env.npm_package_version),
  },
})

Verify the fix

Run only this rule after editing so the report stays focused on the diagnostic you are closing:

pnpm vite-doctor . --framework vite --rules vite/define/no-secret-define
Copyright © 2026