zizmor

Find security issues in GitHub Actions workflows and configurations

brewmacoslinux
Try with needOr install directly
Source

About

Find security issues in GitHub Actions setups

Commands

zizmor

Examples

Scan current directory for security issues in GitHub Actions$ zizmor
Scan a specific workflow file for vulnerabilities$ zizmor .github/workflows/ci.yml
Scan a directory and output results in JSON format$ zizmor .github/workflows --format json