zizmor
Statically audits GitHub Actions workflows, composite actions, Dependabot config, and pre-commit files. Run it offline on a workflow file you already have when CI permissions are in scope.
Tags: github-actions, ci, static-analysis
- Category
- vuln
- Maintenance signal
- active
Use this when: CI trust. Read a workflow file you already have. Do not run it.
Install
brew
brew install zizmorpipx
pipx install zizmorcargo
cargo install --locked zizmorCommand templates
Offline workflow audit
zizmor --offline {file}