# Install smimesign with Homebrew, MacPorts, Nix, scoop, winget

S/MIME signing utility for use with Git. Version 0.2.0 via Homebrew; verified 2026-07-26. Also installable with nix: nix profile install nixpkgs#smimesign.

## Install

```sh
sudo av install brew:smimesign
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install smimesign
```

  Evidence: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install smimesign
```

  Evidence: MacPorts ports tree: security/smimesign/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#smimesign
```

  Evidence: nixpkgs package indexes: pkgs/by-name/sm/smimesign/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

### Windows

- Scoop (92%):

```sh
scoop install main/smimesign
```

  Evidence: Scoop official bucket manifest trees: bucket/smimesign.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id GitHub.smimesign -e
```

  Evidence: Windows Package Manager source index: GitHub.smimesign from https://cdn.winget.microsoft.com/cache/source.msix

## Package facts

- **Package key:** brew:smimesign
- **Package manager:** Homebrew
- **Version:** 0.2.0
- **Source summary:** S/MIME signing utility for use with Git
- **Homepage:** <https://github.com/github/smimesign>
- **Repository:** <https://github.com/github/smimesign>
- **Last updated:** 2026-07-26T04:03:42+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- smimesign (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 0.2.0
## Project history and usage

smimesign is GitHub's S/MIME signing utility for Git commits and tags on macOS and Windows. It matters in CLI packaging because it bridges Git's signing hooks with native X.509 certificate stores instead of requiring GnuPG keys.

### Project history

The official README describes smimesign as an S/MIME signing utility compatible with Git, using X.509 certificates from public or internal certificate authorities. It also states that the tool uses keys and certificates already stored in macOS Keychain or Windows Certificate Store.

### Adoption history

The README documents Homebrew installation on macOS and Scoop installation on Windows, while the supplied package metadata also lists MacPorts, Nix, and winget. This made it installable through the same package managers developers already use for Git tooling.

### How it is used

Users configure Git to invoke smimesign for signing. For Git 2.19 and newer, the README shows setting `gpg.x509.program` to `smimesign` and `gpg.format` to `x509`, either locally per repository or globally for all repositories.

### Why package nerds care

Package maintainers care because smimesign is security-sensitive, platform-specific, and tied to native certificate stores and smart cards. It is also a clear example of package managers distributing small developer-security helpers that integrate with a larger tool, Git.

### Timeline

- 2018: First GitHub release returned by the releases API was 0.0.1.
- 2018: README documents the Git 2.19 configuration split for X.509 signing.
- 2021: Repository release list shows v0.2.0-rc1 as the latest listed release.

### Related projects

- The README discusses Git, GnuPG, PKI, S/MIME, macOS Keychain, Windows Certificate Store, smart cards, OpenSC, and YubiKey PIV tooling.

### Sources

- GitHub releases API for github/smimesign: first listed release 0.0.1 on 2018-09-11.
- <https://github.com/github/smimesign README: purpose, platform support, certificate stores, Git configuration, package-manager installation, smart-card notes.>
- input source_facts.package-manager: Homebrew, MacPorts, Nix, Scoop, and winget package names.


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals

## Other Package-Manager Records

- Nix - smimesign: normalized package name match | nixpkgs package indexes: pkgs/by-name/sm/smimesign/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- MacPorts - smimesign: normalized package name match | MacPorts ports tree: security/smimesign/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Scoop - main/smimesign: normalized package name match | Scoop official bucket manifest trees: bucket/smimesign.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
- winget - GitHub.smimesign: normalized package name match | Windows Package Manager source index: GitHub.smimesign from https://cdn.winget.microsoft.com/cache/source.msix


## Combined YAML source

View the package source record on GitHub. [combined/smimesign.yml](https://github.com/mxcl/pkgdb/blob/main/combined/smimesign.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
