About this project

zizmor is a static analysis tool for CI/CD systems. It scans common CI/CD configurations and reports security problems, with the ability to help fix them. Supported targets include GitHub Actions, Dependabot and pre-commit setups. Among the issues it detects are template injection vulnerabilities that can lead to attacker-controlled code execution, accidental credential persistence and leakage, excessive permission scopes and credential grants to runners, and impostor commits or confusable git references. The project documentation lists additional audits beyond these examples. Installation instructions, a quickstart and detailed usage recipes are provided in the project documentation at docs.zizmor.sh. The tool is distributed via crates.io and appears in several package repositories according to its packaging badge. The project is MIT licensed and accepts contributions through its contributing guide. Development is supported by sponsors, and community discussion takes place on Discord.