zizmor
is a static analysis tool for GitHub Actions. It can find
many common security issues in typical GitHub Actions CI/CD setups.
Important
zizmor
is currently in beta. You will encounter bugs; please file them!
See zizmor
's documentation
for installation steps, as well as a quickstart and
detailed usage recipes.
zizmor
is licensed under the MIT License.
Now you can have beautiful clean workflows!