Audit GitHub Actions for privilege and supply-chain risks with zizmor
Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.
Prerequisites
Python 3.9+ or prebuilt zizmor binary, access to the target repository
Installation
Basic usage or getting-started notes:
-
Extracted from upstream docs: https://raw.githubusercontent.com/zizmorcore/zizmor/HEAD/README.md