awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zizmorcore avatar

zizmorcore/zizmor

0
View on GitHub↗
5,717 stele·220 fork-uri·Rust·MIT·12 vizualizăridocs.zizmor.sh↗

Zizmor

Zizmor is a security linter and static analysis tool designed to audit GitHub Actions workflow files. It functions as a CI/CD security scanner that identifies security vulnerabilities, misconfigurations, and software supply chain risks within automation pipelines.

The project distinguishes itself by providing an automated workflow remediator that applies security fixes to identified vulnerabilities. It also implements a language server for integration with code editors and supports a variety of analysis personas to scale the sensitivity and volume of reported findings.

The tool covers a broad range of security capabilities, including the enforcement of action hash-pinning, detection of secret exposure and hardcoded credentials, and auditing of workflow permissions to ensure least privilege. It also analyzes logic expressions for obfuscation, detects typosquatted actions, and identifies dangerous workflow triggers or injection vectors.

Findings can be exported in SARIF and JSON formats for integration with security dashboards or surfaced as GitHub annotations.

Features

  • GitHub Configuration Audits - Scans GitHub Actions workflows to identify security vulnerabilities, misconfigurations, and supply chain risks.
  • Workflow Security Auditors - Scans GitHub Actions workflow files to identify security vulnerabilities and configuration risks.
  • Vulnerability Detection - Cross-references used actions against the security advisories database to find publicly disclosed vulnerabilities.
  • CI CD Pipelines - Hardens CI/CD pipelines by enforcing least privilege permissions and immutable dependencies.
  • Security Automation Workflows - Integrates automated security scanning into the development process via git hooks, IDEs, and SARIF export.
  • Automated Configuration Remediation - Automatically applies security fixes to identified vulnerabilities in GitHub Actions configuration files.
  • Hardcoded Credential Detection - Identifies plain-text Docker usernames and passwords stored directly within workflow files.
  • Workflow Security Linters - Provides a static analysis tool that scans GitHub Actions workflow files for security vulnerabilities and misconfigurations.
  • Secret Detection - Detects the exposure of the entire secrets context instead of individual secret members.
  • Automated Security Remediation - Resolves a subset of identified security findings automatically using safe correction modes.
  • CI/CD - Audits pipeline configurations to identify supply chain risks and privilege escalation vectors.
  • Software Supply Chain Security - Detects unpinned actions, typosquatted dependencies, and vulnerable third party components within automation workflows.
  • Automated Configuration Remediation - Applies safe programmatic edits to workflow files to automatically resolve identified security misconfigurations.
  • Action Hash Pinning - Enforces the use of immutable SHA references for GitHub Actions to prevent supply chain attacks.
  • Trait-Based Rule Engines - Implements security checks as a set of traits that inspect workflow jobs and steps to identify vulnerabilities.
  • Insecure Trigger Detection - Flags triggers that may allow attacker-controlled code to execute in the target repository context.
  • Permission Auditing Tools - Detects over-scoped permissions at the workflow or job level to enforce the principle of least privilege.
  • YAML AST Analysis - Parses workflow configurations into an abstract syntax tree for deep inspection of logic expressions and structural patterns.
  • Hybrid Data Fetching - Combines local filesystem scanning with remote API calls and caching to analyze both private and public repositories.
  • IDE Analysis Integrations - Provides an LSP implementation that integrates static analysis findings directly into supported code editors.
  • Language Server Implementations - Implements a language server that surfaces security vulnerabilities directly within supported code editors.
  • Security Report Exports - Provides security analysis results in multiple standardized machine-readable and human-readable formats including JSON and SARIF.
  • Workflow Configuration Discovery - Gathers workflow files and action settings from local directories or remote slugs for further inspection.
  • Runner Infrastructure Detectors - Identifies the use of client-managed compute resources which are more difficult to secure than hosted runners.
  • Action Reference Filters - Provides an opt-in mechanism to allowlist or denylist specific action references.
  • Ad-hoc Installation Detection - Identifies run steps that install packages via commands instead of locked manifests to prevent unpinned versions.
  • Analysis Sensitivity Profiles - Adjusts the volume and strictness of reported findings through predefined analysis profiles like pedantic or auditor.
  • Archived Repository Detection - Identifies references to archived repositories to prevent supply chain risks from unmaintained code.
  • Identity Spoofing Detection - Flags bot identity checks using the actor field that can be bypassed by attackers.
  • Build Cache Poisoning Detection - Identifies release workflows that use build state cached from previous executions to prevent attacker code execution.
  • Credential Health Audits - Audits for local filesystem git credential storage and potential leaks of credentials into build artifacts.
  • Log Redaction Audits - Identifies cases where secrets are treated as structured data, preventing them from being redacted from logs.
  • Feature Misconfiguration Detection - Identifies the use of problematic features, such as the Windows CMD shell or specific setup-python inputs.
  • Image Pinning Audits - Identifies container images that lack a hash or specific tag to ensure a predictable runtime environment.
  • Impostor Commit Detection - Identifies pinned references to commits that exist only in forks but appear to belong to the main repository.
  • Insecure Command Detection - Flags the explicit enablement of deprecated and insecure workflow commands via environment variables.
  • Insecure Dependency Execution Detection - Flags configurations that allow external code execution during dependency resolution.
  • Logic Expression Auditing - Detects insecure use of the contains function that allows for substring bypasses.
  • Remote Security Audits - Fetches remote repositories and uses external APIs to provide a deeper analysis of workflow configurations.
  • Secret Inheritance Audits - Detects insecure blanket inheritance of secrets between calling and reusable workflows.
  • Environment-Scoped Secret Management - Identifies the use of secrets outside of a dedicated environment to reduce the risk of exposure.
  • Server-Side Template Injection Detection - Detects template expansions in code contexts that could lead to shell injection via attacker-controllable input.
  • Symbolic Reference Audits - Identifies actions pinned to branches or tags that can be manipulated by attackers to deliver malicious code.
  • Tool Version Pinning Audits - Finds actions that fetch the latest version of an external tool at runtime instead of a pinned version.
  • Typosquatting Detection - Compares action references against a corpus of popular actions to find textual variants owned by different accounts.
  • Custom Security Rule Definitions - Allows defining new analysis rules to detect specific vulnerabilities by implementing traits that inspect workflow jobs.
  • Environment Variable Injection - Identifies dangerous writes to environment and path variables that could lead to arbitrary code execution.
  • Workflow Compliance Auditors - Ensures workflow configurations adhere to organizational standards for naming, documentation, and resource usage.
  • Logic Obfuscation - Identifies redundant path segments or no-op expressions designed to hide the actual behavior of a workflow.
  • LSP Diagnostic Integrations - Uses the Language Server Protocol to surface security findings and diagnostics directly within supported IDEs.
  • Attack and Audit Toolkits - Static analysis tool for securing GitHub Actions workflows.
  • Static Analysis - Security analysis tool for GitHub Actions workflows.
  • Git Repository Analysis - Performs static analysis on GitHub Actions workflows.
  • Vulnerability Auditing - Static analysis for GitHub Actions and CI/CD workflows.

Istoric stele

Graficul istoricului de stele pentru zizmorcore/zizmorGraficul istoricului de stele pentru zizmorcore/zizmor

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru Zizmor

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Zizmor.
  • snyk/snykAvatar snyk

    snyk/snyk

    5,586Vezi pe GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    Vezi pe GitHub↗5,586
  • rhysd/actionlintAvatar rhysd

    rhysd/actionlint

    3,617Vezi pe GitHub↗

    actionlint is a static analysis tool and linter specifically designed for GitHub Actions workflow files. It functions as a CI workflow validator and YAML configuration linter to ensure the syntax and logic of automation files are correct before deployment. The project distinguishes itself by performing deep security auditing and script analysis. It includes a shell script auditor to detect syntax bugs and script injection vulnerabilities in inline commands, and it scans for hardcoded credentials to prevent security leaks. The tool covers a broad range of validation capabilities, including ex

    Goactionscigithub-actions
    Vezi pe GitHub↗3,617
  • bearer/bearerAvatar Bearer

    Bearer/bearer

    2,566Vezi pe GitHub↗

    Bearer is a static analysis security testing tool and privacy compliance auditor. It identifies security vulnerabilities, hard-coded secrets, and privacy risks in source code through static analysis and data flow tracing. The tool distinguishes itself by tracking the movement of sensitive data through code to identify leaks and by mapping personal and health-related information flows to generate evidence for privacy impact assessments. It also provides differential scanning for pull requests and uses fingerprint-based suppression to exclude known false positives from reports. The platform co

    Goappseccode-qualitycompliance
    Vezi pe GitHub↗2,566
  • audreyfeldroy/cookiecutter-pypackageAvatar audreyfeldroy

    audreyfeldroy/cookiecutter-pypackage

    4,584Vezi pe GitHub↗

    This project is a Cookiecutter template for bootstrapping Python packages with a standardized directory layout and configuration files. It provides a foundation for new libraries by generating project structures, boilerplate files, and command-line interface entry points. The template emphasizes a secure software supply chain through hardened build pipelines. It utilizes commit SHA pinning for actions and minimal permission sets to protect against attacks, while providing a setup for building and uploading signed packages to registries using secure identity providers. The project covers a br

    Python
    Vezi pe GitHub↗4,584
Vezi toate cele 30 alternative pentru Zizmor→

Întrebări frecvente

Ce face zizmorcore/zizmor?

Zizmor is a security linter and static analysis tool designed to audit GitHub Actions workflow files. It functions as a CI/CD security scanner that identifies security vulnerabilities, misconfigurations, and software supply chain risks within automation pipelines.

Care sunt principalele funcționalități ale zizmorcore/zizmor?

Principalele funcționalități ale zizmorcore/zizmor sunt: GitHub Configuration Audits, Workflow Security Auditors, Vulnerability Detection, CI CD Pipelines, Security Automation Workflows, Automated Configuration Remediation, Hardcoded Credential Detection, Workflow Security Linters.

Care sunt câteva alternative open-source pentru zizmorcore/zizmor?

Alternativele open-source pentru zizmorcore/zizmor includ: snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… rhysd/actionlint — actionlint is a static analysis tool and linter specifically designed for GitHub Actions workflow files. It functions… bearer/bearer — Bearer is a static analysis security testing tool and privacy compliance auditor. It identifies security… audreyfeldroy/cookiecutter-pypackage — This project is a Cookiecutter template for bootstrapping Python packages with a standardized directory layout and… dxa4481/trufflehog — TruffleHog is a secret scanning tool designed to identify leaked credentials and API keys across version control… analysis-tools-dev/static-analysis — This project is a comprehensive, curated directory of static analysis, linting, and security scanning utilities. It…