# 使用 Homebrew, apk, chocolatey, apt, dnf, MacPorts, Nix, pacman, zypper, scoop, winget 安装 gitleaks

查看 gitleaks 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

## 安装

```sh
sudo av install brew:gitleaks
```

其他安装命令:

### macOS

- Homebrew (100%):

```sh
brew install gitleaks
```

  证据: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install gitleaks
```

  证据: MacPorts ports tree: security/gitleaks/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- apk (92%):

```sh
sudo apk add gitleaks
```

  证据: Alpine Linux edge package indexes: gitleaks from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz

- Debian apt (92%):

```sh
sudo apt install gitleaks
```

  证据: Debian stable package indexes: gitleaks from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install gitleaks
```

  证据: Fedora Rawhide package metadata: gitleaks from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

- Nix (92%):

```sh
nix profile install nixpkgs#gitleaks
```

  证据: nixpkgs package indexes: pkgs/by-name/gi/gitleaks/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S gitleaks
```

  证据: Arch Linux sync databases: gitleaks from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz

- zypper (92%):

```sh
sudo zypper install gitleaks
```

  证据: openSUSE Tumbleweed package metadata: gitleaks from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

### Windows

- Chocolatey (92%):

```sh
choco install gitleaks
```

  证据: Chocolatey community package catalog: gitleaks from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='7.3108','pragmaticworksworkbenchserver'

- Scoop (92%):

```sh
scoop install main/gitleaks
```

  证据: Scoop official bucket manifest trees: bucket/gitleaks.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id Gitleaks.Gitleaks -e
```

  证据: Windows Package Manager source index: Gitleaks.Gitleaks from https://cdn.winget.microsoft.com/cache/source.msix

## 软件包事实

- **软件包键:** brew:gitleaks
- **软件包管理器:** Homebrew
- **版本:** 8.30.1
- **来源摘要:** Audit git repos for secrets
- **主页:** <https://gitleaks.io/>
- **仓库:** <https://github.com/gitleaks/gitleaks>
- **最后更新:** 2026-07-29T16:05:02+02:00
- **已生成:** 2026-08-03T19:37:03+00:00

## 可执行文件

- gitleaks (别名)

## 安装行为

- Bottle: 不可用

## 版本和新鲜度

- 页面生成时间: 2026-08-03
- 管理器版本: 8.30.1
## 项目历史与用法

Gitleaks is an open-source secret scanner for Git repositories, files, directories, and standard input. It is best known as a fast CLI that can run locally, in pre-commit hooks, in containers, or in CI before leaked credentials reach shared history.

### 项目历史

The GitHub repository was created in January 2018 and grew around a rule-based scanner for passwords, API keys, and tokens. The project is written in Go and ships a default TOML configuration containing detection rules and allowlists.

The v8 command model consolidated scanning around git, dir, and stdin modes, while older detect and protect commands were hidden for compatibility. The README later described the project as feature complete, with security patches as the maintenance focus and Betterleaks named as the author's new direction.

### 采用历史

Gitleaks gained strong adoption in the DevSecOps ecosystem because it fits several control points: developer workstations, pre-commit hooks, pull-request checks, scheduled repository scans, and containerized CI jobs. The project homepage cites large Docker, GitHub release, and Homebrew usage figures, and the GitHub repository has a large star and fork count.

The official Gitleaks GitHub Action widened adoption by giving teams a hosted-CI path for scanning pull requests and commits without writing their own wrapper around the CLI.

### 使用方式

Practitioners use gitleaks git to scan repository history, gitleaks dir to scan working trees or exported source, and gitleaks stdin for pipeline streams. Baseline reports let teams suppress already-known findings while failing builds for newly introduced secrets.

Teams customize .gitleaks.toml when they need organization-specific rules, allowlists, report formats, or redaction behavior. In package-manager workflows, the single binary makes it easy to add secret scanning to local development and CI images without a language runtime.

### 为什么软件包爱好者会关心

Gitleaks is a package-manager favorite because it is a Go security utility with broad platform binaries, Docker images, a pre-commit hook, and an official action. That combination makes it easy to pin in reproducible developer environments and CI toolchains.

### 时间线

- 2018: The gitleaks/gitleaks repository was created.
- 2022: v8-era releases emphasized the newer git, dir, and stdin scanning modes.
- 2024: v8.19.0 hid the older detect and protect commands in favor of the newer command names.
- 2026: The README described Gitleaks as feature complete, with future releases focused on security patches.

### Related projects

- Gitleaks Action is the official GitHub Action for running scans on pull requests, commits, or on demand.
- Betterleaks is named by the maintainer as the follow-on project receiving new feature work.

### 来源

- <https://api.github.com/repos/gitleaks/gitleaks>
- <https://github.com/gitleaks/gitleaks>
- <https://gitleaks.io/>
- <https://raw.githubusercontent.com/gitleaks/gitleaks/master/README.md>
- <https://raw.githubusercontent.com/gitleaks/gitleaks/master/config/gitleaks.toml>


## 安全说明

narrow executable package without higher-risk signals.

- **Geiger 风险:** 绿色 / 低
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: (target path)/.gitleaks.toml
## 其他软件包管理器记录

- Debian apt - gitleaks - 8.16.0-1+b12: normalized package name match | Debian stable package indexes: gitleaks from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | protect and discover secrets using Gitleaks 🔑 | https://github.com/gitleaks/gitleaks
- Nix - gitleaks: normalized package name match | nixpkgs package indexes: pkgs/by-name/gi/gitleaks/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - gitleaks - 8.16.0-1build1: normalized package name match | Ubuntu 24.04 LTS package indexes: gitleaks from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | protect and discover secrets using Gitleaks 🔑 | https://github.com/gitleaks/gitleaks
- apk - gitleaks - 8.30.1-r1: normalized package name match | Alpine Linux edge package indexes: gitleaks from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Audit Git repos for secrets and keys | https://github.com/gitleaks/gitleaks
- apk - gitleaks-bash-completion - 8.30.1-r1: normalized package name match | Alpine Linux edge package indexes: gitleaks-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Bash completions for gitleaks | https://github.com/gitleaks/gitleaks
- apk - gitleaks-doc - 8.30.1-r1: normalized package name match | Alpine Linux edge package indexes: gitleaks-doc from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Audit Git repos for secrets and keys (documentation) | https://github.com/gitleaks/gitleaks
- apk - gitleaks-fish-completion - 8.30.1-r1: normalized package name match | Alpine Linux edge package indexes: gitleaks-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Fish completions for gitleaks | https://github.com/gitleaks/gitleaks
- apk - gitleaks-zsh-completion - 8.30.1-r1: normalized package name match | Alpine Linux edge package indexes: gitleaks-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/testing/x86_64/APKINDEX.tar.gz | Zsh completions for gitleaks | https://github.com/gitleaks/gitleaks
- dnf - gitleaks - 8.30.1-2.fc45: normalized package name match | Fedora Rawhide package metadata: gitleaks from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst | Scan git repos (or files) for secrets using regex and entropy | https://github.com/zricethezav/gitleaks
- pacman - gitleaks - 8.30.1-1: normalized package name match | Arch Linux sync databases: gitleaks from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz | Audit Git repos for secrets and keys | https://github.com/gitleaks/gitleaks
- zypper - gitleaks - 8.30.1-1.4: normalized package name match | openSUSE Tumbleweed package metadata: gitleaks from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Protect and discover secrets using Gitleaks | https://github.com/gitleaks/gitleaks
- zypper - gitleaks-bash-completion - 8.30.1-1.4: normalized package name match | openSUSE Tumbleweed package metadata: gitleaks-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Bash Completion for gitleaks | https://github.com/gitleaks/gitleaks
- zypper - gitleaks-fish-completion - 8.30.1-1.4: normalized package name match | openSUSE Tumbleweed package metadata: gitleaks-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Fish Completion for gitleaks | https://github.com/gitleaks/gitleaks
- zypper - gitleaks-zsh-completion - 8.30.1-1.4: normalized package name match | openSUSE Tumbleweed package metadata: gitleaks-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Zsh Completion for gitleaks | https://github.com/gitleaks/gitleaks
- MacPorts - gitleaks: normalized package name match | MacPorts ports tree: security/gitleaks/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- Chocolatey - gitleaks: normalized package name match | Chocolatey community package catalog: gitleaks from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='7.3108','pragmaticworksworkbenchserver'


## Combined YAML source

View the package source record on GitHub. [combined/gitleaks.yml](https://github.com/mxcl/pkgdb/blob/main/combined/gitleaks.yml)


## 来源

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
