Static analysis for GitHub Actions http://docs.zizmor.sh/
Find a file
William Woodruff 7e59e0333b
WIP impostor commit checking
async poisons everything

Signed-off-by: William Woodruff <william@yossarian.net>
2024-08-19 19:04:29 -04:00
src WIP impostor commit checking 2024-08-19 19:04:29 -04:00
.gitignore genesis 2024-08-19 14:26:47 -04:00
Cargo.lock WIP impostor commit checking 2024-08-19 19:04:29 -04:00
Cargo.toml WIP impostor commit checking 2024-08-19 19:04:29 -04:00
README.md README: move roadmap to issue 2024-08-19 14:28:38 -04:00

zizmor

A tool for finding security issues in GitHub Actions CI/CD setups.

At the moment, zizmor only supports workflow definitions, and only detects a small subset of known issues. See the roadmap for details on our plans.

Usage

cargo build
./target/debug/zizmor --help

The name?

Now you can have beautiful clean workflows!