zizmor is a static analysis tool for GitHub Actions.
It can find many common security issues in typical GitHub Actions CI/CD setups,
including:
git references
See zizmor’s documentation
for installation steps, as well as a quickstart and
detailed usage recipes.
zizmor is licensed under the MIT License.
Now you can have beautiful clean workflows!
zizmor’s development is supported by these amazing sponsors!
|
Grafana Labs |
Trail of Bits |
Shipfox |
Kusari |
Tracebit |
| Alexander Riccio |
Want to see your name or logo above? Consider becoming a sponsor
through one of the following: