Automic VaultAutomic Vault

brew

tartufo mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für tartufo in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install tartufo

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#tartufo

nixpkgs package indexes · pkgs/by-name/ta/tartufo/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Searches through git repositories for high entropy strings and secrets

Verlauf

Projektgeschichte und Nutzung

tartufo is a Git secret-scanning CLI from GoDaddy. Its documentation describes scanning repository history and branches for likely secrets using regular expressions and entropy checks, with both local/remote repository scans and pre-commit use.

Projektgeschichte

The official documentation says tartufo was inspired by and built from Dylan Ayrey's truffleHog project. The public changelog begins with v0.0.1 and v0.0.2 on 2019-10-23, followed by v1.0.x releases in November 2019.

The project was substantially reworked for the 2.x line: the changelog describes v2.0.0-era work as a documentation refresh and v2.0.0 alpha as a full restructuring, retesting, rebuilding, and remake that split functionality into subcommands such as pre-commit, scan-local-repo, and scan-remote-repo.

Adoptionsgeschichte

The source facts list tartufo in Homebrew and Nix, while the official quick start documents pip and Docker installation. That combination places it in the common security-tool path of Python package, container image, and package-manager install surfaces.

Wie es verwendet wird

The core CLI use is scanning Git repositories for secrets across history and branches. Official examples show scan-remote-repo, scan-local-repo, and Docker-based scans, and the README notes pre-commit usage for screening changes before commit.

Configuration is TOML-based. Official docs show settings under [tool.tartufo], exclusion signatures, include/exclude path patterns, and custom rule patterns.

Warum Paket-Nerds sich dafür interessieren

Package maintainers care about tartufo because it operationalizes a common repository hygiene task: finding accidentally committed credentials before publishing or while auditing history. Its truffleHog lineage and pre-commit mode make it part of the broader CLI culture around secret scanning in development workflows.

Zeitleiste

  • 2019-10-23: v0.0.1 and v0.0.2 appear in the official project history.
  • 2019-11-19: v1.0.0/v1.0.2 releases appear in the official project history.
  • 2020-10-09: v2.0.0 documents a refreshed 2.0 usage model.
  • 2021-02-04: v2.3.0 switches the primary development branch from master to main.
  • 2022-01-05: v3.0.0 stable release.
  • 2023-01-17: v4.0.0 drops deprecated flags and Python 3.6 support while adding Python 3.11 support.

Related projects

  • truffleHog is named by the official documentation as the project that inspired tartufo.
  • BFG appears in tartufo's changelog as a referenced secret-cleanup tool.

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für tartufo wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 1 Plattformziele verfügbar.
  • Installiert mit 2 Laufzeitabhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
tartufo.tomlpyproject.tomlfiles specified with --config

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
tartufocliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version6.0.0
Manager aktualisiert2026-07-22
lokale DatenOK
Upstreamaktuell
neueste erkannte Versionv6.0.0

https://github.com/godaddy/tartufo

  • OKEs wurden keine Aktualitätswarnungen generiert.

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:tartufo
Version6.0.0
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/tartufo
Homepagehttps://tartufo.readthedocs.io/en/stable/
Repositoryhttps://github.com/godaddy/tartufo
Upstream-Dokumentationhttps://tartufo.readthedocs.io/en/stable
LizenzGPL-2.0-only
Quellarchivhttps://github.com/godaddy/tartufo/archive/refs/tags/v6.0.0.tar.gz
Zuletzt aktualisiert2026-07-22T10:58:05Z
Pulseupdated
Abhängigkeitenpygit2, python@3.14
Von macOS bereitgestellte Bibliothekenlibffi
Bottleverfügbar (auf all)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nametartufo
Version Scheme0
Revision3
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

tartufo

nix profile install nixpkgs#tartufo
  • normalized package name match
  • Abgeglichen nach: Tartufo
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ta/tartufo/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment