AppSecNews
Secret Scanning Open source Established

Talisman

by Thoughtworks

Git hook from Thoughtworks that inspects outgoing changes for credential-shaped content, risky filenames and high entropy strings, and refuses the commit or push.

Visit github.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Talisman in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current detector inventory and any added checks: confirm against repository documentation
  • Scanner mode behavior and report output options: confirm against documentation

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Talisman is a Go binary that installs as a git pre-commit or pre-push hook and examines the changes about to leave the working copy. It runs several independent checks rather than one pattern list. Filename heuristics flag names that alone indicate a credential: private keys, keystores, cloud credential files. Content checks look for private key headers and similar markers. An entropy check computes randomness over base64 and hex character sets and flags strings above a threshold. There are also checks for card numbers and unusually large files, since a large binary in a source repository is often a dump or a keystore.

Suppression is handled by a .talismanrc file recording each accepted file with a checksum of its contents. That is deliberate: if the file changes the checksum no longer matches and it is re-examined, so an ignore entry cannot silently cover a secret added later. A scanner mode runs the same checks across existing history, so you can see what is already there before blocking new commits.

Where it fits

This is a developer laptop control, installed per repository or globally through a git hook template so new clones inherit it. Developers own the experience; a platform team publishes the install instructions and a baseline .talismanrc. Because it is a local hook it prevents rather than detects, and no central record shows it ran. Treat it as a layer beneath a CI scan, not your control of record.

Strengths

  • Multiple detection strategies in one hook, so it catches credential files by name even when the contents match no token format.
  • The checksum-based ignore file prevents the common failure where an exception written once silently covers later changes.
  • A single binary with no runtime dependency, which simplifies distribution across a mixed developer fleet.

Limitations

  • Entropy detection produces a steady stream of false positives on minified assets, generated code, lockfiles and encoded test data, and each one needs an ignore file entry.
  • Being a git hook, it is local and bypassable. A developer can skip verification, an uninstalled clone is unprotected, and findings never leave the machine, so there is nothing you can evidence as a compliance control.
  • It does not validate whether a matched string is a live credential, so severity judgment is manual.

Who it suits

Engineering organizations that want an easily distributed local guardrail and will absorb some false positive friction to catch credential files early. It fits teams already standardizing developer environments. It is not a fit for anyone needing central visibility, verified findings or an auditable record that scanning happened, and should be paired with a CI-side scanner rather than trusted alone.

Used Talisman? Recommend it under your own name and title.

Recommend this tool