zizmor

William Woodruff · zizmor.zizmor

Static analysis for GitHub Actions.

zizmor is a static analysis tool for GitHub Actions. It can find many common security issues in typical GitHub Actions CI/CD setups, including: - Template injection vulnerabilities, leading to attacker-controlled code execution - Accidental credential persistence and leakage - Excessive permission scopes and credential grants to runners - Impostor commits and confusable git references - ...and much more!

winget install --id zizmor.zizmor --exact --source winget

Latest 1.25.2

Release Notes

Bug Fixes πŸ›πŸ”—

  • Fixed a bug where the unpinned-tools audit would incorrectly flag the aquasecurity/trivy-action action as installing an unpinned tool version, rather than aquasecurity/setup-trivy (#2018)

Installer type: zip

Architecture Scope Download SHA256
x64 β€” Download 65D46A8144F701200621B580F632076D80D082D60856DE9F88793A95FB5882D7

Details

Homepage
https://zizmor.sh/
License
MIT
Publisher
William Woodruff
Support
https://github.com/zizmorcore/zizmor/issues
Copyright
Copyright (c) 2024 William Woodruff <william @ yossarian.net>

Tags

github-actionssecuritysecurity-toolsstatic-analysis

Older versions (10)

1.25.1
Architecture Scope Download SHA256
x64 β€” Download C667587918F9F014A85D7955A87DF59DC87DBC0F50969D8AE19A3DFC403419FD
1.25.0
Architecture Scope Download SHA256
x64 β€” Download 63620198D7C1292FDCC3500ABFC7B72F706C99807C5F76E96AC127F1D62254D3
1.24.1
Architecture Scope Download SHA256
x64 β€” Download B777EC2CB1098139BA74B32E30D11ED149C69AB692D23788C466D4A31704BD4B
1.24.0
Architecture Scope Download SHA256
x64 β€” Download 0242E8C2B9886ADAB22BB1748D05EF8155D529A4716BCA33080C6F5C2E2C7C11
1.23.1
Architecture Scope Download SHA256
x64 β€” Download 33C2293FF02834720DD7CD8B47348AAFB2E95A19BDC993C0ECACA9C804ADE92A
1.23.0
Architecture Scope Download SHA256
x64 β€” Download 7707DE90A63A516B653A632D7348B1E089BF7F2C5DAF90CC45CBC4661EB324A0
1.22.0
Architecture Scope Download SHA256
x64 β€” Download 354AD2461D69D255FC7BFB8B359D4486440DF9AE15AF1EFB8F497B9F56F87E74
1.21.0
Architecture Scope Download SHA256
x64 β€” Download 978CFAB35E719D91B88966F0964D3A5E86E37EE3AA67EF7C3ED8E29B11886499
1.20.0
Architecture Scope Download SHA256
x64 β€” Download 01C11F0E0668AE1A46C015BED9F0EC589440606DA928078F6BCA87354C9FDE2F
1.19.0
Architecture Scope Download SHA256
x64 β€” Download D3C1A4A88953349A05F4B1CB5106537C26E23ED416CE3B56E1D0FDEDC75B9AAD