# Tartufo

- **Canonical URI:** https://www.vioscale.ai/software/tartufo
- **Category:** Secrets Scanning
- **Homepage:** https://github.com/godaddy/tartufo
- **Also known as:** tartufo
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-26T19:32:51.357Z

## Vioscale score

**37.8 / 100**, confidence 32% (low). Computed 2026-09-01.

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| price_level | 100 | 0.052 | 5.2 | ✓ |
| reliability | 0 | 0.073 | 0 | - |
| capabilities | 0 | 0.084 | 0 | - |
| repo_stars | 51.2 | 0.026 | 1.3 | ✓ |
| integrations | 8.7 | 0.09355555555555557 | 0.8 | ✓ |
| dependent_projects | 10 | 0.063 | 0.6 | ✓ |
| dev_activity | 0 | 0.094 | 0 | ✓ |
| release_cadence | 80.6 | 0.052 | 4.2 | ✓ |
| security_posture | 0 | 0.073 | 0 | - |
| package_downloads | 0 | 0.136 | 0 | - |
| security_score | 56 | 0.042 | 2.4 | ✓ |
| pricing_transparency | 55 | 0.084 | 4.6 | ✓ |
| community_qa_activity | 0 | 0.063 | 0 | - |

## Pricing

_As of 2026-08-19, [verify at source](https://github.com/pricing). Independently observed._

Open source

## About

Tartufo searches through git repositories to find high entropy strings and secrets that may have been accidentally committed, helping developers identify potential security risks deep in their version control history.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, macOS, Linux, Windows
- **Deployment:** Self-hosted

## Integrations (1)

_Independently observed._

- pre-commit

## Release history

| Version | Date | Type |
|---|---|---|
| [v6.0.0](https://github.com/godaddy/tartufo/releases/tag/v6.0.0) | 2025-11-04 | stable |
| [v5.0.2](https://github.com/godaddy/tartufo/releases/tag/v5.0.2) | 2024-10-17 | stable |
| [v5.0.1](https://github.com/godaddy/tartufo/releases/tag/v5.0.1) | 2024-07-26 | stable |
| [v5.0.0](https://github.com/godaddy/tartufo/releases/tag/v5.0.0) | 2024-03-14 | stable |
| [v4.1.0](https://github.com/godaddy/tartufo/releases/tag/v4.1.0) | 2023-04-03 | stable |
| [v4.0.1](https://github.com/godaddy/tartufo/releases/tag/v4.0.1) | 2023-03-01 | stable |
| [v4.0.0](https://github.com/godaddy/tartufo/releases/tag/v4.0.0) | 2023-01-17 | stable |
| [v3.3.1](https://github.com/godaddy/tartufo/releases/tag/v3.3.1) | 2022-11-23 | stable |
| [v3.3.0](https://github.com/godaddy/tartufo/releases/tag/v3.3.0) | 2022-11-23 | stable |
| [v3.2.1](https://github.com/godaddy/tartufo/releases/tag/v3.2.1) | 2022-07-20 | stable |
| [v3.2.0](https://github.com/godaddy/tartufo/releases/tag/v3.2.0) | 2022-07-06 | stable |
| [v3.1.4](https://github.com/godaddy/tartufo/releases/tag/v3.1.4) | 2022-05-31 | stable |
| [v3.1.3](https://github.com/godaddy/tartufo/releases/tag/v3.1.3) | 2022-04-04 | stable |
| [v3.1.2](https://github.com/godaddy/tartufo/releases/tag/v3.1.2) | 2022-03-28 | stable |
| [v3.1.1](https://github.com/godaddy/tartufo/releases/tag/v3.1.1) | 2022-03-25 | stable |

_… and 5 earlier release(s)._

## Security & compliance


Known vulnerabilities: 0 (0 in the last 12 months) ([source](https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=tartufo&per_page=100)). A count reflects scale and disclosure, not quality.

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 1 | [link](https://github.com/pricing) | 2026-08-19 | 60% (medium) |

### market

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | [link](https://github.com/pricing) | 2026-08-19 | 75% (high) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.price_level | free | [link](https://github.com/pricing) | 2026-08-19 | 60% (medium) |
| pricing.transparent | yes | [link](https://github.com/pricing) | 2026-08-19 | 60% (medium) |
| pricing.model | commercial | [link](https://github.com/godaddy/tartufo) | 2026-08-26 | 40% (low) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 0 | [link](https://github.com/godaddy/tartufo/pulse) | 2026-08-26 | 65% (medium) |

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 517 | [link](https://github.com/godaddy/tartufo) | 2026-08-26 | 90% (high) |
| adoption.dependent_repos | 3 | [link](https://packages.ecosyste.ms/api/v1/packages/lookup?repository_url=https%3A%2F%2Fgithub.com%2Fgodaddy%2Ftartufo) | 2026-08-26 | 85% (high) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Python | [link](https://github.com/godaddy/tartufo) | 2026-08-26 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | GPL-2.0 | [link](https://github.com/godaddy/tartufo) | 2026-08-26 | 95% (high) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 35 | [link](https://github.com/godaddy/tartufo/releases) | 2026-08-26 | 70% (medium) |

### security

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| security.scorecard | 5.6 | [link](https://api.securityscorecards.dev/projects/github.com/godaddy/tartufo) | 2026-08-26 | 90% (high) |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=tartufo&per_page=100","last_12m":0,"max_severity":null}` | [link](https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=tartufo&per_page=100) | 2026-08-26 | 90% (high) |

---
*Source: Vioscale (https://www.vioscale.ai/software/tartufo). Independent, evidence-based software intelligence. Cite the canonical URI.*
