pkg.soopen package index

brew / rank 8587

Install pivit with Homebrew

Sign and verify data using hardware (Yubikey) backed x509 certificates (PIV). Version 0.9.3 via Homebrew; verified 2026-09-11.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install pivit

local Homebrew formula metadata

overview

Package summary

Sign and verify data using hardware (Yubikey) backed x509 certificates (PIV)

Commands and aliases

  • pivit

history

Project history and usage

Pivit manages X.509 certificates on PIV-compatible smart cards and performs hardware-backed signing and verification.

Project history

Cash App developed Pivit as a Go command-line tool for managing X.509 certificates held by PIV-compatible smart cards and for using those certificates to sign and verify data.

Adoption history

Pivit is distributed through Homebrew and can also be installed directly as a Go command.

How it is used

Users can configure Git with `gpg.format x509` and `gpg.x509.program pivit`, initialize a YubiKey PIV applet, generate hardware-resident keys, create certificate requests, and sign or verify commits and tags.

Why package nerds care

Pivit connects package-installed command-line tooling with hardware-backed developer identity. Its compatibility with Git's external signing-program interface makes PIV smart cards and YubiKeys usable in workflows commonly served by OpenPGP or SSH signing tools.

Timeline

  • Initial public development: Cash App published Pivit as an open-source Go command-line utility.
  • Current usage: Pivit supports smart-card initialization, key generation, certificate workflows, and Git-compatible X.509 signing.

Related projects

  • Pivit integrates with Git's X.509 signing interface and targets PIV applets such as those available on YubiKeys.

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 2 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
pivitcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version0.9.3
manager updated2026-09-11
local dataok
upstreamcurrent
latest detectedv0.9.3

https://github.com/cashapp/pivit

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:pivit
Version0.9.3
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/pivit
Homepagehttps://github.com/cashapp/pivit
Repositoryhttps://github.com/cashapp/pivit
LicenseMIT
Source archivehttps://github.com/cashapp/pivit/archive/refs/tags/v0.9.3.tar.gz
Last updated2026-09-11T13:03:31Z
Pulseupdated
Build dependenciesgo, pkgconf
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepivit
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation