# Install terrahash with Homebrew

Create and store a hash of the Terraform modules used by your configuration. Version 0.1.0 via Homebrew; verified 2026-07-26.

## Install

```sh
sudo av install brew:terrahash
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install terrahash
```

  Evidence: local Homebrew formula metadata

## Package facts

- **Package key:** brew:terrahash
- **Package manager:** Homebrew
- **Version:** 0.1.0
- **Source summary:** Create and store a hash of the Terraform modules used by your configuration
- **Homepage:** <https://github.com/ned1313/terrahash>
- **Repository:** <https://github.com/ned1313/terrahash>
- **Last updated:** 2026-07-26T00:50:36+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- terrahash (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 0.1.0
## Project history and usage

TerraHash is a small Terraform module-locking CLI that creates and checks hashes for modules used by a Terraform configuration.

### Project history

The public GitHub repository was created in June 2024. Its README explicitly labels the project as early-stage software, while documenting the core behavior: evaluate initialized Terraform configuration, generate hashes for modules, and store them in a .terraform.module.lock.hcl file analogous to Terraform's provider lock file.

The tool's narrow purpose is supply-chain control for Terraform modules. It checks the lock file against current module hashes and version constraints, then reports changed hashes, changed versions, or missing modules.

### Adoption history

Adoption appears niche and security-focused rather than broad. Repository metadata showed a small but visible public audience by July 2026, and Homebrew metadata lists a brew formula for the CLI.

### How it is used

The README describes three central commands: terrahash init to create a module lock file, terrahash check to validate current modules against it, and terrahash upgrade to update the lock file after approved changes.

The project is meant to run in CI so deployments can fail when Terraform module code or version constraints diverge from the approved lock file.

### Why package nerds care

For package nerds, TerraHash is interesting because it fills a small gap in Terraform's lock-file story: Terraform has a provider lock file, while this tool experiments with a separate module lock file that can be installed as a simple CLI.

### Timeline

- 2024: Public GitHub repository created.
- 2024: README documents init, check, and upgrade workflows around .terraform.module.lock.hcl.
- 2026: Homebrew metadata lists terrahash as a packaged CLI.

### Related projects

- Terraform supplies the module system and provider lock-file pattern that TerraHash mirrors.
- Terragrunt and Terramate are adjacent Terraform workflow tools, but TerraHash is focused specifically on module hash verification.

### Sources

- Input package metadata: source_facts.package-manager, source_facts.package-manager-url
- README: https://github.com/ned1313/terrahash#readme
- Repository metadata: https://api.github.com/repos/ned1313/terrahash


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals


## Combined YAML source

View the package source record on GitHub. [combined/terrahash.yml](https://github.com/mxcl/pkgdb/blob/main/combined/terrahash.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
