# Install tartufo with Homebrew, Nix

Searches through git repositories for high entropy strings and secrets. Version 6.0.0 via Homebrew; verified 2026-07-25. Also installable with nix: nix profile install nixpkgs#tartufo.

## Install

```sh
sudo av install brew:tartufo
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install tartufo
```

  Evidence: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#tartufo
```

  Evidence: nixpkgs package indexes: pkgs/by-name/ta/tartufo/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:tartufo
- **Package manager:** Homebrew
- **Version:** 6.0.0
- **Source summary:** Searches through git repositories for high entropy strings and secrets
- **Homepage:** <https://tartufo.readthedocs.io/en/stable/>
- **Repository:** <https://github.com/godaddy/tartufo>
- **Last updated:** 2026-07-25T10:47:16Z
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- tartufo (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 6.0.0
## Project history and usage

tartufo is a Git secret-scanning CLI from GoDaddy. Its documentation describes scanning repository history and branches for likely secrets using regular expressions and entropy checks, with both local/remote repository scans and pre-commit use.

### Project history

The official documentation says tartufo was inspired by and built from Dylan Ayrey's truffleHog project. The public changelog begins with v0.0.1 and v0.0.2 on 2019-10-23, followed by v1.0.x releases in November 2019.

The project was substantially reworked for the 2.x line: the changelog describes v2.0.0-era work as a documentation refresh and v2.0.0 alpha as a full restructuring, retesting, rebuilding, and remake that split functionality into subcommands such as pre-commit, scan-local-repo, and scan-remote-repo.

### Adoption history

The source facts list tartufo in Homebrew and Nix, while the official quick start documents pip and Docker installation. That combination places it in the common security-tool path of Python package, container image, and package-manager install surfaces.

### How it is used

The core CLI use is scanning Git repositories for secrets across history and branches. Official examples show scan-remote-repo, scan-local-repo, and Docker-based scans, and the README notes pre-commit usage for screening changes before commit.

Configuration is TOML-based. Official docs show settings under [tool.tartufo], exclusion signatures, include/exclude path patterns, and custom rule patterns.

### Why package nerds care

Package maintainers care about tartufo because it operationalizes a common repository hygiene task: finding accidentally committed credentials before publishing or while auditing history. Its truffleHog lineage and pre-commit mode make it part of the broader CLI culture around secret scanning in development workflows.

### Timeline

- 2019-10-23: v0.0.1 and v0.0.2 appear in the official project history.
- 2019-11-19: v1.0.0/v1.0.2 releases appear in the official project history.
- 2020-10-09: v2.0.0 documents a refreshed 2.0 usage model.
- 2021-02-04: v2.3.0 switches the primary development branch from master to main.
- 2022-01-05: v3.0.0 stable release.
- 2023-01-17: v4.0.0 drops deprecated flags and Python 3.6 support while adding Python 3.11 support.

### Related projects

- truffleHog is named by the official documentation as the project that inspired tartufo.
- BFG appears in tartufo's changelog as a referenced secret-cleanup tool.

### Sources

- <https://tartufo.readthedocs.io/en/stable/>
- <https://tartufo.readthedocs.io/en/stable/changelog.html>
- <https://tartufo.readthedocs.io/en/stable/configuration.html>
- source_facts.package-manager


## Security Notes

No matching local secret-handling manifest was found for tartufo. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: tartufo.toml, pyproject.toml, files specified with --config
## Other Package-Manager Records

- Nix - tartufo: normalized package name match | nixpkgs package indexes: pkgs/by-name/ta/tartufo/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/tartufo.yml](https://github.com/mxcl/pkgdb/blob/main/combined/tartufo.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
