pkg.sopackage field notes

brew / rank 1680

Install ggshield with Homebrew

Scanner for secrets and sensitive data in code. Version 1.53.0 via Homebrew; verified 2026-07-30.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install ggshield

provider-native install command

overview

Package summary

Scanner for secrets and sensitive data in code

Commands and aliases

  • ggshield

history

Project history and usage

ggshield is GitGuardian's open-source command-line scanner for detecting hardcoded secrets and sensitive data before they reach source-control history or CI artifacts.

Project history

GitGuardian opened the ggshield repository in April 2020 and published the early 1.0.x release line soon afterward. The project is built as the local and CI-facing companion to GitGuardian's secret-detection service, using the GitGuardian public API through the py-gitguardian client.

Adoption history

The tool gained adoption through several security workflows rather than one single editor or platform: local scans, pre-commit and pre-push hooks, CI/CD jobs, GitHub Actions, GitLab, Jenkins, Docker-image scans, package scans, and packaged distribution through PyPI, Homebrew, Chocolatey, Cloudsmith packages, and standalone installers.

How it is used

Practitioners authenticate with `ggshield auth login` or an API key, then scan paths, repositories, staged changes, Docker images, package artifacts, or CI workspaces. Teams commonly install it as a pre-commit, pre-push, or pre-receive hook so leaked credentials are blocked before they enter shared repositories.

Why package nerds care

For package ecosystems, ggshield is notable because it packages a SaaS-backed security control as a normal developer CLI: it can be installed by a package manager, run in a hook, and produce exit codes that fit standard CI pipelines.

Timeline

  • 2020: The GitGuardian ggshield repository was created.
  • 2020: The 1.0.x release line appeared in the GitHub release feed.
  • 2026: The release feed showed the 1.52 series.

Related projects

  • ggshield is closely tied to GitGuardian's public API and py-gitguardian client, and it overlaps operationally with pre-commit, CI/CD systems, and repository-hosting security workflows.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for ggshield. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.gitguardian.yaml./.gitguardian.yaml
Windows
%USERPROFILE%\.gitguardian.yaml.\.gitguardian.yaml

executables

Installed executables

CommandKindExposureNote
ggshieldexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version1.53.0
manager updated2026-07-30
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:ggshield
Version1.53.0
Package managerHomebrew
Homepagehttps://www.gitguardian.com
Repositoryhttps://github.com/GitGuardian/ggshield
Last updated2026-07-30T01:29:14Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation