zizmor

Static analysis for GitHub Actions

MIT 64 个版本 Python >=3.10
William Woodruff <william@yossarian.net> <William Woodruff <william@yossarian.net>>
安装
pip install zizmor
poetry add zizmor
pipenv install zizmor
conda install zizmor
描述

🌈 zizmor

zizmor CI Crates.io Packaging status GitHub Sponsors Discord

zizmor is a static analysis tool for GitHub Actions.

It can find many common security issues in typical GitHub Actions CI/CD setups, including:

  • Template injection vulnerabilities, leading to attacker-controlled code execution
  • Accidental credential persistence and leakage
  • Excessive permission scopes and credential grants to runners
  • Impostor commits and confusable git references
  • ...and much more!

zizmor demo

See zizmor's documentation for installation steps, as well as a quickstart and detailed usage recipes.

License

zizmor is licensed under the MIT License.

Contributing

See our contributing guide!

The name?

Now you can have beautiful clean workflows!

Sponsors

zizmor's development is supported by these amazing sponsors!

Logo-level sponsors

Grafana Labs

Trail of Bits

Shipfox

Kusari

Tracebit

Name-level sponsors
Alexander Riccio Carol Willing

Want to see your name or logo above? Consider becoming a sponsor through one of the following:

Star History

Star History Chart
版本列表
1.26.1 2026-06-21
1.26.0 2026-06-21
1.25.2 2026-05-16
1.25.1 2026-05-15
1.25.0 2026-05-14
1.24.1 2026-04-13
1.24.0 2026-04-13
1.24.0rc3 2026-04-13
1.24.0rc2 2026-04-13
1.23.1 2026-03-08
1.23.0 2026-03-08
1.23.0rc7 2026-03-08
1.23.0rc6 2026-03-08
1.23.0rc5 2026-02-25
1.23.0rc1 2026-02-23
1.22.0 2026-01-17
1.21.0 2026-01-16
1.20.0 2026-01-06
1.19.0 2025-12-18
1.18.0 2025-11-29
1.18.0rc3 2025-11-29
1.18.0rc2 2025-11-29
1.17.0 2025-11-25
1.16.3 2025-11-05
1.16.2 2025-11-02
1.16.1 2025-10-29
1.16.0 2025-10-24
1.15.2 2025-10-14
1.15.1 2025-10-14
1.15.0 2025-10-13
1.14.2 2025-09-29
1.14.1 2025-09-26
1.14.0 2025-09-26
1.13.0 2025-09-12
1.12.1 2025-08-15
1.12.0 2025-08-13
1.11.0 2025-06-30
1.11.1rc1 2025-07-02
1.10.0 2025-06-26
1.9.0 2025-05-30
1.8.0 2025-05-20
1.8.0rc2 2025-05-20
1.8.0rc1 2025-05-20
1.7.0 2025-05-09
1.6.0 2025-04-20
1.5.2 2025-03-23
1.5.1 2025-03-12
1.5.0 2025-03-11
1.4.1 2025-02-25
1.4.0 2025-02-25
1.3.1 2025-02-09
1.3.0 2025-01-29
1.2.2 2025-01-19
1.2.1 2025-01-18
1.2.0 2025-01-18
1.1.1 2025-01-13
1.1.0 2025-01-13
1.0.1 2025-01-07
1.0.0 2025-01-02
0.10.0 2024-12-19
0.9.2 2024-12-15
0.9.1 2024-12-12
0.9.0 2024-12-12
0.8.0 2024-12-06