Static analysis for GitHub Actions http://docs.zizmor.sh/
Find a file
William Woodruff b517d6c1d4
Workflow: keep the raw workflow around
...this will be useful when building
accurate spans.

Signed-off-by: William Woodruff <william@yossarian.net>
2024-08-23 17:28:37 -04:00
src Workflow: keep the raw workflow around 2024-08-23 17:28:37 -04:00
.gitignore genesis 2024-08-19 14:26:47 -04:00
Cargo.lock expel async from the codebase 2024-08-21 23:19:01 -04:00
Cargo.toml expel async from the codebase 2024-08-21 23:19:01 -04:00
README.md README: move roadmap to issue 2024-08-19 14:28:38 -04:00

zizmor

A tool for finding security issues in GitHub Actions CI/CD setups.

At the moment, zizmor only supports workflow definitions, and only detects a small subset of known issues. See the roadmap for details on our plans.

Usage

cargo build
./target/debug/zizmor --help

The name?

Now you can have beautiful clean workflows!