zizmor

Crates.iozizmor
lib.rszizmor
version1.12.1
created_at2024-10-27 19:43:08.182938+00
updated_at2025-08-15 04:33:18.601339+00
descriptionStatic analysis for GitHub Actions
homepagehttps://docs.zizmor.sh
repositoryhttps://github.com/zizmorcore/zizmor
max_upload_size
id1424909
size1,298,798
William Woodruff (woodruffw)

documentation

https://docs.zizmor.sh

README

🌈 zizmor

zizmor CI Crates.io Packaging status GitHub Sponsors Discord

zizmor is a static analysis tool for GitHub Actions.

It can find many common security issues in typical GitHub Actions CI/CD setups, including:

  • Template injection vulnerabilities, leading to attacker-controlled code execution
  • Accidental credential persistence and leakage
  • Excessive permission scopes and credential grants to runners
  • Impostor commits and confusable git references
  • ...and much more!

zizmor demo

See zizmor's documentation for installation steps, as well as a quickstart and detailed usage recipes.

License

zizmor is licensed under the MIT License.

Contributing

See our contributing guide!

The name?

Now you can have beautiful clean workflows!

Sponsors 💖

zizmor's development is supported by these amazing sponsors!

Logo-level sponsors

Grafana Labs

Trail of Bits

Name-level sponsors
Tenki Cloud Alexander Riccio

Want to see your name or logo above? Consider becoming a sponsor through one of the following:

Star History

Star History Chart
Commit count: 725

cargo fmt