# Install talisman with Homebrew

Tool to detect and prevent secrets from getting checked in. Version 1.37.0 via Homebrew; verified 2026-07-26.

## Install

```sh
sudo av install brew:talisman
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install talisman
```

  Evidence: provider-native install command

## Package facts

- **Package key:** brew:talisman
- **Package manager:** Homebrew
- **Version:** 1.37.0
- **Source summary:** Tool to detect and prevent secrets from getting checked in
- **Homepage:** <https://thoughtworks.github.io/talisman/>
- **Repository:** <https://github.com/thoughtworks/talisman>
- **Last updated:** 2026-07-26T00:50:32+02:00
- **Generated:** 2026-08-03T00:40:33+00:00

## Executables

- talisman (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.37.0
## Project history and usage

Talisman is a Thoughtworks-maintained secret-scanning CLI and Git-hook tool. It became package-manager relevant because it packages a common DevSecOps guardrail as a local binary that can run before code leaves a developer workstation.

### Project history

The official repository was initialized on 2015-12-14 and the first observed release tag, v0.1.0, is dated 2016-04-19. Its README defines the project as a tool that scans Git changesets so likely secrets or sensitive information do not leave the developer's workstation.

### Adoption history

Talisman is distributed as a standalone executable, as a repository Git hook, and as a global Git hook template. The official README documents Homebrew installation, release-page binaries, an install script, pre-commit integration, and Husky integration, which placed it in the same day-to-day tooling layer as linters and formatters.

### How it is used

The standard usage is to install the `talisman` binary and invoke it from pre-commit or pre-push hooks. It checks outgoing changesets for patterns such as SSH keys, authorization tokens, and private keys; it can also run directly as a CLI utility for Git repository scanning.

### Why package nerds care

Package nerds care about Talisman because it is a classic local-policy binary: small enough to install with Homebrew, easy to pin in hook frameworks, and useful before centralized secret-scanning infrastructure ever sees a commit. Its documented auto-update behavior from v0.4.4 also reflects the tension between reproducible pinned tooling and security tools that want to stay current.

### Timeline

- 2015-12-14: First commits in the official Git repository.
- 2016-04-19: First observed release tag, v0.1.0.
- 2018-10-08: v0.3.1 appears in the tag history before the README-documented v0.4.4 auto-update behavior.
- 2025-05-02: v1.37.0 appears as the latest observed tag and Homebrew stable version.

### Related projects

- Talisman is commonly used with Git hooks, pre-commit, and Husky. In package-manager culture it sits beside tools such as git-secrets and detect-secrets, though this record relies only on the official Talisman sources for claims.

### Sources

- <https://formulae.brew.sh/api/formula/talisman.json>
- <https://github.com/thoughtworks/talisman README>
- <https://github.com/thoughtworks/talisman official Git history and tags>


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: .talismanrc

## Combined YAML source

View the package source record on GitHub. [combined/talisman.yml](https://github.com/automic-vault/db/blob/main/combined/talisman.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
