# 🌈 zizmor [![zizmor](https://img.shields.io/badge/%F0%9F%8C%88-zizmor-white?labelColor=white)](https://zizmor.sh/) [![CI](https://github.com/zizmorcore/zizmor/actions/workflows/ci.yml/badge.svg)](https://github.com/zizmorcore/zizmor/actions/workflows/ci.yml) [![Crates.io](https://img.shields.io/crates/v/zizmor)](https://crates.io/crates/zizmor) [![Packaging status](https://repology.org/badge/tiny-repos/zizmor.svg)](https://repology.org/project/zizmor/versions) [![GitHub Sponsors](https://img.shields.io/github/sponsors/woodruffw?style=flat&logo=githubsponsors&labelColor=white&color=white)](https://github.com/sponsors/woodruffw) [![Discord](https://img.shields.io/badge/Discord-%235865F2.svg?logo=discord&logoColor=white)](https://discord.com/invite/PGU3zGZuGG) `zizmor` is a static analysis tool for GitHub Actions. It can find many common security issues in typical GitHub Actions CI/CD setups, including: * Template injection vulnerabilities, leading to attacker-controlled code execution * Accidental credential persistence and leakage * Excessive permission scopes and credential grants to runners * Impostor commits and confusable `git` references * ...[and much more]! [and much more]: https://docs.zizmor.sh/audits/ ![zizmor demo](https://zizmor.sh/assets/zizmor-demo.gif) See [`zizmor`'s documentation](https://docs.zizmor.sh/) for [installation steps], as well as a [quickstart] and [detailed usage recipes]. [please file them]: https://github.com/zizmorcore/zizmor/issues/new?assignees=&labels=bug%2Ctriage&projects=&template=bug-report.yml&title=%5BBUG%5D%3A+ [installation steps]: https://docs.zizmor.sh/installation/ [quickstart]: https://docs.zizmor.sh/quickstart/ [detailed usage recipes]: https://docs.zizmor.sh/usage/ ## License `zizmor` is licensed under the [MIT License](./LICENSE). ## Contributing See [our contributing guide!](./CONTRIBUTING.md) ## The name? *[Now you can have beautiful clean workflows!]* [Now you can have beautiful clean workflows!]: https://www.youtube.com/watch?v=ol7rxFCvpy8 ## Sponsors 💖 `zizmor`'s development is supported by these amazing sponsors!
Logo-level sponsors

Grafana Labs

Trail of Bits

Shipfox

Name-level sponsors
Alexander Riccio
Want to see your name or logo above? Consider becoming a sponsor through one of the following: - [GitHub Sponsors](https://github.com/sponsors/woodruffw) (preferred) - [thanks.dev](https://thanks.dev/u/gh/woodruffw) - [ko-fi](https://ko-fi.com/woodruffw) ## Star History Star History Chart