Static analysis for GitHub Actions http://docs.zizmor.sh/
Find a file
William Woodruff 31093d0a72
locate: handle non-job keys properly
Signed-off-by: William Woodruff <william@yossarian.net>
2024-08-26 18:50:46 -04:00
src locate: handle non-job keys properly 2024-08-26 18:50:46 -04:00
.gitignore genesis 2024-08-19 14:26:47 -04:00
Cargo.lock Use tree-sitter to concretize locations (#4) 2024-08-26 18:07:14 -04:00
Cargo.toml Use tree-sitter to concretize locations (#4) 2024-08-26 18:07:14 -04:00
README.md README: move roadmap to issue 2024-08-19 14:28:38 -04:00

zizmor

A tool for finding security issues in GitHub Actions CI/CD setups.

At the moment, zizmor only supports workflow definitions, and only detects a small subset of known issues. See the roadmap for details on our plans.

Usage

cargo build
./target/debug/zizmor --help

The name?

Now you can have beautiful clean workflows!