# @godaddy/tartufo-node

> Ensures Tartufo is available for npm-based projects

Latest version **0.3.3** (published 2023-01-30) · MIT license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install @godaddy/tartufo-node
pnpm add @godaddy/tartufo-node
yarn add @godaddy/tartufo-node
bun add @godaddy/tartufo-node
```

Provides the commands `tartufo`, `tartufo-helper`.

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 0.3.3 |
| Published | 2023-01-30 |
| First published | 2021-07-16 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=14 |
| Dependencies | 5 |
| Unpacked size | 25.1 KB |
| Known vulnerabilities | 0 |
| Install scripts | yes |
| GitHub stars | 6 |
| Author | GoDaddy Operating Company, LLC |
| Maintainers | mmason2, jpina1-godaddy, jacopodaeli, jgowdy, ibrandao, decompil3d, jpage, kinetifex, rxmarbles, kquerna, 3rdeden, jcrugzz, dcousineau |

## Links

- npm: https://www.npmjs.com/package/@godaddy/tartufo-node
- Repository: https://github.com/godaddy/tartufo-node
- Homepage: https://github.com/godaddy/tartufo-node#readme
- Issues: https://github.com/godaddy/tartufo-node/issues
- npm.io page: https://npm.io/package/@godaddy/tartufo-node

## Dependencies (5)

- [chalk](https://npm.io/package/chalk.md) ^4.1.2
- [debug](https://npm.io/package/debug.md) ^4.3.4
- [lookpath](https://npm.io/package/lookpath.md) ^1.2.2
- [global-dirs](https://npm.io/package/global-dirs.md) ^3.0.1
- [is-installed-globally](https://npm.io/package/is-installed-globally.md) ^0.4.0

## Recent versions

- 0.3.3 (latest) — 2023-01-30
- 0.4.0 — 2023-01-30
- 0.3.2 — 2022-10-05
- 0.3.1 — 2022-03-31
- 0.3.0 — 2022-03-31
- 0.2.1 — 2022-02-17
- 0.2.0 — 2022-01-07
- 0.1.0 — 2021-07-16

## README

# Tartufo, Managed By npm!

[Tartufo](https://tartufo.readthedocs.io/en/stable/) is an open-source project provides tooling to look for and find secrets that may or may not have been accidentally committed to code. It provides a wonderful pre-commit mode that is perfect for keeping repositories clean of committed secrets.

This package exists to help orchestrate making sure Tartufo is available for use by local developers working in pure-javascript projects. When installed into your projects, it will provide a local you can use in your `package.json` scripts.

This package _prefers_ to use a globally-installed tartufo _if present_, otherwise it will install a local copy.

## Prerequisites

This package requires that Python 3.6+ be installed and available. It expects to find python either at the command `python3` or `python` if the former is not available.

**This package does not currently support Windows!**

### Installing Python on a Mac

We recommend using [Homebrew](https://brew.sh) to install Python via `brew install python`.

### Installing Python on Linux

Please follow your distro's recommendations for installing Python.

### Installing Python on Windows

_Windows is not yet supported with this package. This documentation will be udpated when it is supported._

## Installing

Run `npm install --save-dev @godaddy/tartufo-node` to install in your local project

## Example usage

You can use `tartufo` like any other npm-provided bin, for example to use tartufo as a pre-commit you could combine it with [Husky](https://github.com/typicode/husky#readme):

Add the following to your `package.json`:

```json
{
  "scripts": {
    "tartufo:pre-commit": "tartufo pre-commit"
  }
}
```

Then tell Husky to run the command on pre-commit:

```bash
npx husky add .husky/pre-commit "npm run tartufo:pre-commit"
git add .husky/pre-commit
```

Alternatively you could work with tartufo directly via npx, for example you could run `npx tartufo --help` in your project to see command line tools available to you.

## Troubleshooting

This package provides a `tartufo-helper` tool to help diagnose issues locally. To do so, run `npx tartufo-helper doctor` to see debugging output. If necessary, it may recommend you run `npx tartufo-helper reset` to reset your local installation.

## How it works

This package takes advantage of `preinstall` and `postinstall` npm lifecycle hooks. When installing into your package, two things will happen:

First, the `preinstall` script will validate your local environment and fail if it cannot find Python 3.6+.

Second `postinstall` script will check if you have `tartufo` available globally. If so, the `postinstall` script will exit as there is nothing to do!

However if no `tartufo` is available, it will create a [venv](https://docs.python.org/3/library/venv.html) locally (in the `node_modules` folder) and use pip to install tartufo.

---
_Source: https://npm.io/package/@godaddy/tartufo-node · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
