
Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including template injection, credential leakage, and permission misconfigurations.
zizmor is a static analysis tool for CI/CD systems.
It can find and fix security issues in common CI/CD setups, including GitHub Actions,
Dependabot, and pre-commit. Some of the things zizmor finds:
git references
See zizmor's documentation
for installation steps, as well as a quickstart and
detailed usage recipes.
zizmor is licensed under the MIT License.
Now you can have beautiful clean workflows!
zizmor's development is supported by these amazing sponsors!
| Alexander Riccio | Carol Willing |
Want to see your name or logo above? Consider becoming a sponsor through one of the following:
Grafana Labs |
Trail of Bits |
Kusari |
Tracebit |