zizmor

by zizmorcore · Security

Static analysis for GitHub Actions

New0 ratings6,458 starsActive
SecurityDeveloper ToolRustPython
Open project ↗↓ Download v1.30.0GitHub⚑ Report
zizmor preview

About this project

🌈 zizmor zizmor is a static analysis tool for CI/CD systems. It can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit. Some of the things zizmor finds: Template injection vulnerabilities, leading to attacker-controlled code execution Accidental credential persistence and leakage Excessive permission scopes and credential grants to runners Impostor commits and confusable git references ...[and much more]! See zizmor's documentation for [installation steps], as well as a [quickstart] and [detailed usage recipes]. License zizmor is licensed under the MIT License. Contributing See our…

Technologies

ShellPythonRustDockerfileMakefilegithub-actionssecuritysecurity-tools

Project health

Actively maintained
Last updateyesterday
Contributors110
Latest releasev1.30.0
Open issues & PRs166
LicenseMIT
On GitHubsince 2024

GitHub

6,458
stars
247
forks
110
contributors
166
open issues & PRs
Rust
language
yesterday
last commit
View on GitHub ↗All releases ↗

Reviews

out of 5 · 0 ratings
★★★★★
0%
★★★★
0%
★★★
0%
★★
0%
0%
Sign in to write a review
No reviews yet
Be the first to review zizmor.

Built by

zizmorcore
Imported from GitHub · not yet claimed on GitPalace
View developer pageSign in with GitHub to claim

Maintain zizmorcore/zizmor? Claiming verifies admin access through your GitHub account and gives you control of this listing.

You might also like