Home

The devel/zizmor port

zizmor-1.24.1 – static analysis tool for GitHub Actions (cvsweb github mirror)

Description

zizmor is a static analysis tool for GitHub Actions.

It can find many common issues in typical GitHub Actions CI/CD setups,
including:

* Template injection vulnerabilities, leading to attacker-controlled
  code execution
* Accidental credential persistence and leakage
* Excessive permission scopes and credential grants to runners
* Impostor commits and confusable git references
WWW: https://docs.zizmor.sh/

Maintainer

Theo Buehler

Only for arches

aarch64 alpha amd64 arm hppa i386 mips64 mips64el powerpc powerpc64 riscv64 sparc64

Categories

devel lang/rust

Build dependencies

Files

Search