homebrew.txt_□×

homebrew tap.

My CLI tools ship through one Homebrew tap, llbbl/tap, which lives atgithub.com/llbbl/homebrew-tap. Each formula installs a prebuilt binary from that project's GitHub releases, and the tap picks up new releases on its own.

formulae

  • lsm

    Per-app, per-environment secrets manager. Values are age-encrypted at rest.

  • dfm

    Manage, version, and AI-improve your dotfiles, with a private backup repo for history.

  • upkeep

    Maintenance toolkit for JavaScript and TypeScript repositories.

  • uncov

    Reports files with low test coverage from Vitest and Istanbul output.

recommended: trust the whole tap

Tap it, trust it once, and install whatever you want from it:

brew tap llbbl/tap
brew trust --tap llbbl/tap
brew install lsm dfm upkeep uncov

Tap trust covers every current and future formula, cask, and external command inllbbl/tap, so when a new tool lands here it is a plainbrew install <name> away.

why trust is required

Since Homebrew 6.0.0 (June 2026), taps outside Homebrew's official ones need explicit trust. Formulae, casks, and external commands are executable Ruby, not plain metadata, so trusting a tap means accepting that its code may run with your user's privileges whenever Homebrew loads it.

The check guards against compromised repos, ownership changes, package name collisions, and unintended command execution. Untrusted taps and items fail to load until you trust them, and brew doctor warns about untrusted non-official taps. Details are inHomebrew's tap trust docs.

narrower: one tool at a time

Homebrew's docs prefer trusting only the item you need, and keep whole-tap trust for taps you use often. If you only want one tool, or you're scripting installs, trust a single formula:

brew tap llbbl/tap
brew trust --formula llbbl/tap/lsm
brew install lsm

Or install by fully qualified name, which trusts only that formula with no separate trust step:

brew install llbbl/tap/lsm

list and revoke trust

See what you trust:

brew trust

Revoke the whole tap. This also clears any per-formula trust under it:

brew untrust --tap llbbl/tap

If you trusted single formulae instead, revoke them one at a time. A formula stays trusted while its tap is trusted.

brew untrust --formula llbbl/tap/lsm

migrating uncov from the old tap

uncov used to live in its own tap, llbbl/uncov. New installs use the shared tap:

brew install llbbl/tap/uncov

If you already have it from llbbl/uncov:

brew tap llbbl/tap
brew trust --formula llbbl/tap/uncov
brew update
brew upgrade llbbl/tap/uncov

If the migration was skipped earlier, run brew reinstall llbbl/tap/uncov. Once brew info uncov shows the shared tap, remove the old one withbrew untap llbbl/uncov.

Update any Brewfiles or scripts from llbbl/uncov/uncov tollbbl/tap/uncov.

START
llbbl.exeprojects/posts/experiments/subscribe.dlg
© 2026v1.0.0