zizmorcore/zizmor

Static analysis for GitHub Actions

6,451

stars

1,534

commits

Rust

primary language

Sep 4, 2026

updated

docs.zizmor.sh/
github-actions
security
security-tools
static-analysis
Browse cluster: Secret Detection & Data Leak Prevention

README

🌈 zizmor

zizmor CI Crates.io Packaging status GitHub Sponsors Discord

zizmor is a static analysis tool for CI/CD systems.

It can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit. Some of the things zizmor finds:

  • Template injection vulnerabilities, leading to attacker-controlled code execution
  • Accidental credential persistence and leakage
  • Excessive permission scopes and credential grants to runners
  • Impostor commits and confusable git references
  • ...and much more!

zizmor demo

See zizmor's documentation for installation steps, as well as a quickstart and detailed usage recipes.

License

zizmor is licensed under the MIT License.

Contributing

See our contributing guide!

The name?

Now you can have beautiful clean workflows!

Sponsors

zizmor's development is supported by these amazing sponsors!


Want to see your name or logo above? Consider becoming a sponsor through one of the following:

Star History

Star History Chart

Contributors

(top 30 of 108)

woodruffw

1,083 commits

dependabot[bot]

179 commits

ubiratansoares

23 commits

zizmorcore/zizmor

Static analysis for GitHub Actions

6,451

stars

1,534

commits

Rust

primary language

Sep 4, 2026

updated

docs.zizmor.sh/
github-actions
security
security-tools
static-analysis
Browse cluster: Secret Detection & Data Leak Prevention

README

🌈 zizmor

zizmor CI Crates.io Packaging status GitHub Sponsors Discord

zizmor is a static analysis tool for CI/CD systems.

It can find and fix security issues in common CI/CD setups, including GitHub Actions, Dependabot, and pre-commit. Some of the things zizmor finds:

  • Template injection vulnerabilities, leading to attacker-controlled code execution
  • Accidental credential persistence and leakage
  • Excessive permission scopes and credential grants to runners
  • Impostor commits and confusable git references
  • ...and much more!

zizmor demo

See zizmor's documentation for installation steps, as well as a quickstart and detailed usage recipes.

License

zizmor is licensed under the MIT License.

Contributing

See our contributing guide!

The name?

Now you can have beautiful clean workflows!

Sponsors

zizmor's development is supported by these amazing sponsors!


Want to see your name or logo above? Consider becoming a sponsor through one of the following:

Star History

Star History Chart

Contributors

(top 30 of 108)

woodruffw

1,083 commits

dependabot[bot]

179 commits

ubiratansoares

23 commits

Languages

Rust

98.2%

Python

1.6%