pkg.soopen package index

brew / rank 10200

Install shush with Homebrew, apt

Encrypt and decrypt secrets using the AWS Key Management Service. Version 1.5.5 via Homebrew; verified 2026-09-13. Also installable with ubuntu: sudo apt install shush.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install shush

local Homebrew formula metadata

overview

Package summary

Encrypt and decrypt secrets using the AWS Key Management Service

Commands and aliases

  • shush

history

Project history and usage

shush is a Go command-line utility from REA Group for encrypting and decrypting small secrets with AWS Key Management Service.

Project history

REA Group developed shush as a small AWS KMS encryption and decryption tool. The official repository's copyright notice dates from 2019, and the project was implemented in Go with downloadable release binaries.

Adoption history

The official project publishes release binaries, documents installation with go install, and provides a direct Unix/Linux installation example. Its exec mode also supports container-entrypoint use, broadening it from an interactive encryption utility into a deployment-time secret injector.

How it is used

Pipe plaintext to shush encrypt with a KMS key ID, ARN, or alias, then pipe the Base64 ciphertext to shush decrypt. The exec subcommand decrypts KMS_ENCRYPTED_ environment variables and exposes the plaintext under names without that prefix before starting another command.

Why package nerds care

shush is representative of small cloud-native security utilities that wrap a managed key service in Unix pipes and environment-variable conventions. Its command-shim mode is particularly relevant to container and twelve-factor deployment workflows.

Timeline

  • 2019: Year in the official repository copyright notice.
  • 1.5.5: Version used in the official binary-installation and container examples.

Related projects

  • AWS KMS provides the cryptographic service and AWS SDK credential chain. The official README also points to ssssh as a Ruby-compatible alternative and shows how AWS CLI plus base64 can reproduce the basic decrypt workflow.

Sources

  • Official repository and README: https://github.com/realestate-com-au/shush

security posture

Risk level: blue

broad file, network, media, or database tool signal.

Risk classifier

blue risk · medium confidence · tool

Why

  • broad file, network, media, or database tool signal

Signals

  • text:encrypt,decrypt

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 8 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.aws/credentials

executables

Installed executables

CommandKindExposureNote
shushcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version1.5.5
manager updated2026-09-13
local dataok
upstreamcurrent
latest detectedv1.5.5

https://github.com/realestate-com-au/shush

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:shush
Version1.5.5
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/shush
Homepagehttps://github.com/realestate-com-au/shush
Repositoryhttps://github.com/realestate-com-au/shush
LicenseMIT
Source archivehttps://github.com/realestate-com-au/shush/archive/refs/tags/v1.5.5.tar.gz
Last updated2026-09-13T09:11:47Z
Pulseupdated
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, sonoma, ventura, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameshush
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Ubuntu apt95%

shush 1.2.3-5.1

runs a command and optionally reports its output by mail

http://web.taranis.org/shush/

sudo apt install shush
  • Section: universe/admin
  • Architecture: amd64
  • 2 dependencies
  • normalized package name match
  • Matched by: Shush
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: shush from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation