Integrate Talisman with Vulnetix. Install Talisman as a git pre-commit or pre-push hook to prevent hardcoded secrets, private keys, and sensitive files from entering your repositories.
Install & scan
$ # Install via script (adds to global git hooks directory) bash -c "$(curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/main/install.sh)" # macOS with Homebrew brew install talisman # Install as pre-commit hook in current repo talisman -g pre-commit $ # Scan the full git history of the current repository talisman --scan # Scan with report to specific directory talisman --scan --reportdirectory=/tmp/talisman-reports
Run Talisman in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install Talisman
run: |
curl -L https://github.com/thoughtworks/talisman/releases/latest/download/talisman_linux_amd64 -o talisman
chmod +x talisman && sudo mv talisman /usr/local/bin/
- name: Scan repository for secrets
run: talisman --scan --reportdirectory=/tmp/talisman-report
- name: Upload to Vulnetix
run: vulnetix upload --file /tmp/talisman-report/talisman_report.json
How Vulnetix compares: better together
Vulnetix does not replace Talisman. Keep running it. Vulnetix sits on top of Talisman (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
| Capability | Vulnetix | Talisman |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✓ Core: entropy + filename + credit-card + encoded-secret detection as a git hook |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Talisman does well
- Purpose-built git pre-commit/pre-push hook that stops secrets before they ever reach history, developer-local prevention rather than after-the-fact detection
- Broad heuristic net: high-entropy strings, Base64/hex encoded secrets, suspicious filenames (.pem/.key/id_rsa), credit-card numbers and large files
- Configurable severity thresholds, custom patterns and language scoping (Go/Node/PHP/Python) via .talismanrc to cut false positives
- CLI scan mode audits full repository history, plus a checksum calculator for bulk ignore management
Where Vulnetix adds to it: Talisman is a developer-local prevention hook; Vulnetix does not replace that shift-left gate. Vulnetix ingests findings and provides the org-wide layer Talisman lacks, cross-scanner dedup into one queue, exploit-intel prioritisation, reachability, versioned VEX, autofix and SSVC. Better together: keep Talisman blocking commits on the developer's machine, let Vulnetix consolidate and govern secrets alongside every other scanner class.
No migration, no rip-and-replace. Talisman keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Talisman results in Vulnetix
Upload Talisman JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.