zizmor
Static analysis for GitHub Actions
About this project
🌈 zizmor zizmor is a static analysis tool for CI/CD systems. It can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit. Some of the things zizmor finds: Template injection vulnerabilities, leading to attacker-controlled code execution Accidental credential persistence and leakage Excessive permission scopes and credential grants to runners Impostor commits and confusable git references ...[and much more]! See zizmor's documentation for [installation steps], as well as a [quickstart] and [detailed usage recipes]. License zizmor is licensed under the MIT License. Contributing See our…
Technologies
Project health
GitHub
Reviews
Built by
Maintain zizmorcore/zizmor? Claiming verifies admin access through your GitHub account and gives you control of this listing.