35 releases (14 stable)
Uses new Rust 2024
new 1.5.2 | Mar 23, 2025 |
---|---|
1.4.1 | Feb 25, 2025 |
0.10.0 | Dec 19, 2024 |
0.6.0 | Nov 26, 2024 |
#6 in Command line utilities
6,925 downloads per month
315KB
7K
SLoC
🌈 zizmor
zizmor
is a static analysis tool for GitHub Actions.
It can find many common security issues in typical GitHub Actions CI/CD setups, including:
- Template injection vulnerabilities, leading to attacker-controlled code execution
- Accidental credential persistence and leakage
- Excessive permission scopes and credential grants to runners
- Impostor commits and confusable
git
references - ...and much more!
See zizmor
's documentation
for installation steps, as well as a quickstart and
detailed usage recipes.
License
zizmor
is licensed under the MIT License.
Contributing
The name?
Now you can have beautiful clean workflows!
Sponsors 💖
zizmor
's development is supported by these amazing sponsors!
Astral |
Star History
Dependencies
~41–57MB
~1M SLoC