# Gitleaks vs Tartufo

| Attribute | Gitleaks | Tartufo |
|---|---|---|
| **Vioscale score** | 53.3 (20% (low)) | 37.8 (32% (low)) |
| activity.commits_last_30d | - | 0 |
| adoption.dependent_repos | 0 | 3 |
| adoption.github_stars | 28,963 | 517 |
| deployment.options | `{"cloud":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | An open-source utility that automatically scans git repositories, individual files, and directories to identify secrets and sensitive credentials. It integrates with GitHub Actions to enable continuous secret scanning on pull requests and commits. | Tartufo searches through git repositories to find high entropy strings and secrets that may have been accidentally committed, helping developers identify potential security risks deep in their version control history. |
| integrations.count | 1 | 1 |
| integrations.list | `[{"name":"GitHub"}]` | `[{"name":"pre-commit"}]` |
| language.primary | Go | Python |
| license.spdx | MIT | GPL-2.0 |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"mac":true,"linux":true,"windows":true}` |
| pricing | `{"type":"open_source","summary":"Free and open-source","freeTier":true,"sourceUrl":"https://gitleaks.io","retrievedAt":"2026-08-19T21:35:55.718Z"}` | `{"type":"open_source","sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-19T21:37:59.570Z"}` |
| pricing.free_tier | yes | - |
| pricing.model | commercial | commercial |
| pricing.price_level | free | free |
| pricing.transparent | yes | yes |
| release.cadence_days | 13 | 35 |
| release.history | `[{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.30.1","date":"2026-03-21T02:17:58Z","type":"stable","version":"v8.30.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.30.0","date":"2025-11-26T16:31:23Z","type":"stable","version":"v8.30.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.29.1","date":"2025-11-19T21:18:33Z","type":"stable","version":"v8.29.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.29.0","date":"2025-11-04T21:42:27Z","type":"stable","version":"v8.29.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.28.0","date":"2025-07-20T16:18:38Z","type":"stable","version":"v8.28.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.27.2","date":"2025-06-09T00:35:40Z","type":"stable","version":"v8.27.2"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.27.1","date":"2025-06-08T01:59:23Z","type":"stable","version":"v8.27.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.27.0","date":"2025-06-01T16:36:05Z","type":"stable","version":"v8.27.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.26.0","date":"2025-05-12T21:03:12Z","type":"stable","version":"v8.26.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.25.1","date":"2025-04-30T13:51:27Z","type":"stable","version":"v8.25.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.25.0","date":"2025-04-29T14:53:48Z","type":"stable","version":"v8.25.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.24.3","date":"2025-04-11T14:27:15Z","type":"stable","version":"v8.24.3"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.24.2","date":"2025-03-22T12:08:54Z","type":"stable","version":"v8.24.2"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.24.0","date":"2025-02-20T02:11:45Z","type":"stable","version":"v8.24.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.23.3","date":"2025-01-29T14:46:14Z","type":"stable","version":"v8.23.3"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.23.2","date":"2025-01-24T14:25:35Z","type":"stable","version":"v8.23.2"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.23.1","date":"2025-01-15T12:51:08Z","type":"stable","version":"v8.23.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.23.0","date":"2025-01-13T15:04:20Z","type":"stable","version":"v8.23.0"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.22.1","date":"2024-12-30T16:25:05Z","type":"stable","version":"v8.22.1"},{"url":"https://github.com/gitleaks/gitleaks/releases/tag/v8.22.0","date":"2024-12-20T16:12:19Z","type":"stable","version":"v8.22.0"}]` | `[{"url":"https://github.com/godaddy/tartufo/releases/tag/v6.0.0","date":"2025-11-04T17:31:21Z","type":"stable","version":"v6.0.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v5.0.2","date":"2024-10-17T23:16:06Z","type":"stable","version":"v5.0.2"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v5.0.1","date":"2024-07-26T13:27:30Z","type":"stable","version":"v5.0.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v5.0.0","date":"2024-03-14T21:30:15Z","type":"stable","version":"v5.0.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v4.1.0","date":"2023-04-03T20:45:09Z","type":"stable","version":"v4.1.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v4.0.1","date":"2023-03-01T21:01:54Z","type":"stable","version":"v4.0.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v4.0.0","date":"2023-01-17T23:18:37Z","type":"stable","version":"v4.0.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.3.1","date":"2022-11-23T22:04:17Z","type":"stable","version":"v3.3.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.3.0","date":"2022-11-23T00:35:22Z","type":"stable","version":"v3.3.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.2.1","date":"2022-07-20T18:32:33Z","type":"stable","version":"v3.2.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.2.0","date":"2022-07-06T19:57:46Z","type":"stable","version":"v3.2.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.1.4","date":"2022-05-31T23:25:41Z","type":"stable","version":"v3.1.4"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.1.3","date":"2022-04-04T23:36:35Z","type":"stable","version":"v3.1.3"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.1.2","date":"2022-03-28T22:43:26Z","type":"stable","version":"v3.1.2"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.1.1","date":"2022-03-25T15:32:19Z","type":"stable","version":"v3.1.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.1.0","date":"2022-03-24T21:30:25Z","type":"stable","version":"v3.1.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.0.0","date":"2022-01-05T22:56:38Z","type":"stable","version":"v3.0.0"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v2.10.1","date":"2021-12-27T20:33:47Z","type":"stable","version":"v2.10.1"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.0.0-rc.3","date":"2021-12-13T21:58:57Z","type":"prerelease","version":"v3.0.0-rc.3"},{"url":"https://github.com/godaddy/tartufo/releases/tag/v3.0.0-rc.2","date":"2021-12-10T00:58:17Z","type":"prerelease","version":"v3.0.0-rc.2"}]` |
| security.scorecard | - | 5.6 |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=debian&package_name=gitleaks&per_page=100","last_12m":0,"max_severity":null}` | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=tartufo&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (Secrets Scanning)

| Capability | Gitleaks | Tartufo |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Git repository historical scanning | - | - |
| Pre commit developer hooks | - | - |
| Active token validation engine | - | - |
| High entropy regex detection | - | - |
| Slack teams jira scanning | - | - |
| Automated key revocation apis | - | - |
| Custom regex rules support | - | - |
| Ci cd pipeline build blocking | - | - |
| Compliance audit reporting | - | - |
| SOC2 type ii | - | - |
| ISO 27001 | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T16:33:51.472Z. "-" = undocumented, not absent.*
