zizmorcore/zizmor
Static analysis for GitHub Actions observed · 2026-08-28
Health v2 · maintenance only
84/100
- Activity 99
- Release rhythm 83
- Longevity 53
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 4
- age_days: 744
- days_rel: 32
- days_push: 8
- n_releases_24m: 72
Adoption not part of the score
6394 stars · 242 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
zizmor is a static analysis tool for CI/CD configurations, primarily GitHub Actions workflows, as well as Dependabot and pre-commit configs. It detects security issues like template injection, credential leakage, and excessive permissions, and can auto-fix some findings.
Use cases
- scan github actions workflows for security vulnerabilities
- find template injection in ci pipelines
- detect leaked credentials in workflows
- audit workflow permission scopes
- add security scanning to github actions ci
- lint github actions workflow files
When to choose
- you maintain GitHub Actions workflows and want automated security audits
- you need SARIF output for GitHub code scanning
- you want to catch template injection and credential persistence before attackers do
When to avoid
- you need static analysis for non-CI/CD code (use a general SAST tool)
- you don't use GitHub Actions, Dependabot, or pre-commit
Facets
cli-tool · maturity active
security linter vulnerability-scanning cli ci-cd security developer-tools cli cross-platform windows rust github-actions cicd-security sarif dependabot pre-commit supply-chain-security devops automation linux macos docker
6 sources
- readme: https://github.com/zizmorcore/zizmor · fetched 2026-08-28 · f961fe9a6923
- homepage: http://docs.zizmor.sh/ · fetched 2026-08-29 · 626511da89ad
- site_page: https://docs.zizmor.sh/installation · fetched 2026-08-29 · 84097c3e533b
- site_page: https://docs.zizmor.sh/quickstart · fetched 2026-08-29 · 0c1a28d9eaad
- site_page: https://docs.zizmor.sh/integrations · fetched 2026-08-29 · 77827a428a5c
- registry_crates: https://crates.io/api/v1/crates/zizmor · fetched 2026-08-29 · ef9c454f7a20
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| zizmorcore/zizmor | main | 84 |
For agents
markdown · JSON · MCP: product_card(name="zizmorcore/zizmor")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem