
Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed or pushed to repositories.
A tool to detect and prevent secrets from getting checked in
Talisman is a tool that scans git changesets to ensure that potential secrets or sensitive information do not leave the developer's workstation.
It validates the outgoing changeset for things that look suspicious - such as potential SSH keys, authorization tokens, private keys etc.
Talisman supports MAC OSX, Linux and Windows.
Talisman can be installed and used in one of the following ways:
Talisman can be set up as either a pre-commit or pre-push hook on the git repositories.
Find the instructions below.
Disclaimer: Secrets creeping in via a forced push in a git repository cannot be detected by Talisman. A forced push is believed to be notorious in its own ways, and we suggest git repository admins to apply appropriate measures to authorize such activities.
We recommend installing talisman onto your path so that it is available for
git hook frameworks and scripts. Pick the correct binary for your system from
our Releases Page, or run
our install script:
bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/install.sh)"
Or set environment variable INSTALL_LOCATION to specify a custom location for
the binary:
INSTALL_LOCATION=/usr/local/bin bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/install.sh)"
Or set environment variable VERSION to a released tag to install a specific version::
VERSION=v1.36.0 bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/install.sh)"
Or using linuxbrew in Linux and homebrew in macOS by running the following command in terminal:
brew install talisman
We offer scripts that will install Talisman as a pre-commit git hook template, as that will cause Talisman to be present, not only in your existing git repositories, but also in any new repository that you 'init' or 'clone'.
As a pre-commit hook:
bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/global_install_scripts/install.bash)"
OR
As a pre-push hook:
bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/global_install_scripts/install.bash)" -- pre-push
$PATH, you will be asked an appropriate place to set it up. Choose the option number where you set the profile source on your machine.Remember to execute source on the path file or restart your terminal.
If you choose to set the $PATH later, please export TALISMAN_HOME=$HOME/.talisman/bin to the path.
Globally installing talisman as a hook will not clobber any existing hooks. If the installation script finds any existing hooks, it will only indicate so on the console. To run multiple hooks we suggest using a hook framework, such as pre-commit or husky. These instructions assume that the talisman executable is installed somewhere on your system's path.
Use pre-commit to manage existing hooks along with
Talisman. Reference our pre-commit-hooks in your
.pre-commit-config.yaml:
- repo: https://github.com/thoughtworks/talisman
rev: 'v1.32.2' # Update me!
hooks:
# both pre-commit and pre-push supported
# - id: talisman-push
- id: talisman-commit
husky is an npm module for managing hooks.
Add the following line to the husky pre-commit configuration in your
package.json:
talisman --githook pre-commit
Once the talisman executable is installed you can configure a standalone pre-commit hook for a git repository:
cd my-git-project
echo "talisman -g pre-commit" >> .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit
Since release v0.4.4, Talisman automatically updates the binary to the latest release, when the hook is invoked (at pre-commit/pre-push, as set up). So, just sit back, relax, and keep using the latest Talisman without any extra efforts.