# Source-control packages

Source-control packages can read or mutate repositories, issue trackers, release flows, and authenticated developer state.

- **Packages:** 438
- **Protected tools:** 0
- **Approval gates:** 2
- **Non-low risk:** 59
- **Updated:** 2026-08-03

## Why this package group is here

Source-control packages currently includes 438 package catalog entries. 0 have protected-tool coverage, 2 have approval-gate metadata, and 59 have non-low Geiger classifier findings. The grouping comes from package metadata, so it can stay current as that metadata changes.

## Generated source

This hub uses the same local package data as individual package pages: Nucleus package metadata, Homebrew enrichment, Geiger classifier output, secret-handling manifests, and approval-gate seeds where available.

## Review model

Use the hub to find command families that need tighter secret injection, approval gates, or manual review before agents run them.

## Indexed package pages

- [gh](https://pkg.so/pkg/brew/gh/) - 7 approval-gate rules are present.
- [git](https://pkg.so/pkg/brew/git/) - 6 approval-gate rules are present.
- [llvm](https://pkg.so/pkg/brew/llvm/) - compiler and toolchain runtime
- [nushell](https://pkg.so/pkg/brew/nushell/) - generalized runtime or code generation signal
- [texlive](https://pkg.so/pkg/brew/texlive/) - broad file, network, media, or database tool signal
- [gitlogue](https://pkg.so/pkg/brew/gitlogue/) - generalized runtime or code generation signal
- [vcprompt](https://pkg.so/pkg/brew/vcprompt/) - broad file, network, media, or database tool signal
- [git-if](https://pkg.so/pkg/brew/git-if/) - generalized runtime or code generation signal
- [glib](https://pkg.so/pkg/brew/glib/) - library-like package without higher-risk signals
- [libgit2](https://pkg.so/pkg/brew/libgit2/) - library-like package without higher-risk signals
- [glab](https://pkg.so/pkg/brew/glab/) - no executable entrypoint in the package index
- [git-lfs](https://pkg.so/pkg/brew/git-lfs/) - narrow executable package without higher-risk signals
- [lazygit](https://pkg.so/pkg/brew/lazygit/) - narrow executable package without higher-risk signals
- [bat](https://pkg.so/pkg/brew/bat/) - narrow executable package without higher-risk signals
- [actionlint](https://pkg.so/pkg/brew/actionlint/) - no executable entrypoint in the package index
- [pre-commit](https://pkg.so/pkg/brew/pre-commit/) - narrow executable package without higher-risk signals
- [gitleaks](https://pkg.so/pkg/brew/gitleaks/) - narrow executable package without higher-risk signals
- [git-filter-repo](https://pkg.so/pkg/brew/git-filter-repo/) - narrow executable package without higher-risk signals
- [git-delta](https://pkg.so/pkg/brew/git-delta/) - narrow executable package without higher-risk signals
- [act](https://pkg.so/pkg/brew/act/) - narrow executable package without higher-risk signals
- [trufflehog](https://pkg.so/pkg/brew/trufflehog/) - no executable entrypoint in the package index
- [git-gui](https://pkg.so/pkg/brew/git-gui/) - narrow executable package without higher-risk signals
- [zizmor](https://pkg.so/pkg/brew/zizmor/) - no executable entrypoint in the package index
- [jj](https://pkg.so/pkg/brew/jj/) - no executable entrypoint in the package index
- [lefthook](https://pkg.so/pkg/brew/lefthook/) - no executable entrypoint in the package index
- [prek](https://pkg.so/pkg/brew/prek/) - no executable entrypoint in the package index
- [git-flow](https://pkg.so/pkg/brew/git-flow/) - narrow executable package without higher-risk signals
- [tig](https://pkg.so/pkg/brew/tig/) - narrow executable package without higher-risk signals
- [difftastic](https://pkg.so/pkg/brew/difftastic/) - narrow executable package without higher-risk signals
- [mercurial](https://pkg.so/pkg/brew/mercurial/) - no executable entrypoint in the package index
- [worktrunk](https://pkg.so/pkg/brew/worktrunk/) - no executable entrypoint in the package index
- [flyway](https://pkg.so/pkg/brew/flyway/) - no executable entrypoint in the package index
- [repomix](https://pkg.so/pkg/brew/repomix/) - narrow executable package without higher-risk signals
- [commitizen](https://pkg.so/pkg/brew/commitizen/) - no executable entrypoint in the package index
- [talisman](https://pkg.so/pkg/brew/talisman/) - narrow executable package without higher-risk signals
- [diff-so-fancy](https://pkg.so/pkg/brew/diff-so-fancy/) - narrow executable package without higher-risk signals
- [gitui](https://pkg.so/pkg/brew/gitui/) - narrow executable package without higher-risk signals
- [ghq](https://pkg.so/pkg/brew/ghq/) - narrow executable package without higher-risk signals
- [hub](https://pkg.so/pkg/brew/hub/) - narrow executable package without higher-risk signals
- [repo](https://pkg.so/pkg/brew/repo/) - no executable entrypoint in the package index
- [bfg](https://pkg.so/pkg/brew/bfg/) - narrow executable package without higher-risk signals
- [tea](https://pkg.so/pkg/brew/tea/) - no executable entrypoint in the package index
- [github-mcp-server](https://pkg.so/pkg/brew/github-mcp-server/) - no executable entrypoint in the package index
- [ggshield](https://pkg.so/pkg/brew/ggshield/) - no executable entrypoint in the package index
- [dvc](https://pkg.so/pkg/brew/dvc/) - no executable entrypoint in the package index
- [jjui](https://pkg.so/pkg/brew/jjui/) - no executable entrypoint in the package index
- [git-svn](https://pkg.so/pkg/brew/git-svn/) - narrow executable package without higher-risk signals
- [gitversion](https://pkg.so/pkg/brew/gitversion/) - narrow executable package without higher-risk signals
- [notmuch](https://pkg.so/pkg/brew/notmuch/) - narrow executable package without higher-risk signals
- [claude-squad](https://pkg.so/pkg/brew/claude-squad/) - narrow executable package without higher-risk signals
- [git-extras](https://pkg.so/pkg/brew/git-extras/) - no executable entrypoint in the package index
- [grip](https://pkg.so/pkg/brew/grip/) - no executable entrypoint in the package index
- [git-secrets](https://pkg.so/pkg/brew/git-secrets/) - narrow executable package without higher-risk signals
- [backlog-md](https://pkg.so/pkg/brew/backlog-md/) - no executable entrypoint in the package index
- [tf-summarize](https://pkg.so/pkg/brew/tf-summarize/) - narrow executable package without higher-risk signals
- [gastown](https://pkg.so/pkg/brew/gastown/) - narrow executable package without higher-risk signals
- [git-secret](https://pkg.so/pkg/brew/git-secret/) - narrow executable package without higher-risk signals
- [git-cliff](https://pkg.so/pkg/brew/git-cliff/) - narrow executable package without higher-risk signals
- [onefetch](https://pkg.so/pkg/brew/onefetch/) - narrow executable package without higher-risk signals
- [git-town](https://pkg.so/pkg/brew/git-town/) - no executable entrypoint in the package index
- [cocogitto](https://pkg.so/pkg/brew/cocogitto/) - narrow executable package without higher-risk signals
- [pinact](https://pkg.so/pkg/brew/pinact/) - no executable entrypoint in the package index
- [gopass](https://pkg.so/pkg/brew/gopass/) - narrow executable package without higher-risk signals
- [git-quick-stats](https://pkg.so/pkg/brew/git-quick-stats/) - narrow executable package without higher-risk signals
- [git-spice](https://pkg.so/pkg/brew/git-spice/) - narrow executable package without higher-risk signals
- [git-format-staged](https://pkg.so/pkg/brew/git-format-staged/) - narrow executable package without higher-risk signals
- [mergiraf](https://pkg.so/pkg/brew/mergiraf/) - no executable entrypoint in the package index
- [gibo](https://pkg.so/pkg/brew/gibo/) - narrow executable package without higher-risk signals
- [transcrypt](https://pkg.so/pkg/brew/transcrypt/) - no executable entrypoint in the package index
- [git-cola](https://pkg.so/pkg/brew/git-cola/) - narrow executable package without higher-risk signals
- [git-remote-codecommit](https://pkg.so/pkg/brew/git-remote-codecommit/) - no executable entrypoint in the package index
- [serie](https://pkg.so/pkg/brew/serie/) - narrow executable package without higher-risk signals
