{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security"}],"enrichment":{"capability":"zizmor is a static analysis tool that scans CI/CD configurations\u2014GitHub Actions, Dependabot, and pre-commit\u2014to identify and fix security vulnerabilities like template injection, credential leakage, and excessive permission grants.","skillfed_tags":["ci-cd-security","static-analysis","github-actions"],"use_cases":["Audit GitHub Actions workflows before merging to catch template injection and credential exposure risks.","Scan Dependabot configurations to ensure dependency updates don't grant excessive permissions.","Validate pre-commit hook setups to prevent compromised hooks from executing arbitrary code.","Integrate into CI pipelines to enforce security checks on workflow file changes.","Review existing workflow repositories for historical misconfigurations and permission creep."],"what_it_does":"zizmor is a static analysis tool designed to audit CI/CD pipelines for security misconfigurations. It examines GitHub Actions workflows, Dependabot configurations, and pre-commit hooks to detect vulnerabilities including template injection that could lead to code execution, accidental credential persistence, overly broad permission grants, and git reference spoofing. The tool runs locally as a command-line utility with no external dependencies, making it straightforward to integrate into development workflows or CI systems themselves.\n\nThe package is actively maintained, recently released, and backed by established security organizations. It targets modern Python (3.10+) and ships as pre-built wheels for common platforms, eliminating compilation friction. With no runtime dependencies and permissive MIT licensing, it presents minimal adoption barriers for teams seeking to harden their CI/CD security posture.","worth_installing":"Yes. zizmor addresses a genuine gap in CI/CD security tooling with active maintenance, zero runtime dependencies, permissive licensing, and broad platform support. It is worth installing if you use GitHub Actions, Dependabot, or pre-commit and want to catch configuration-level security issues before they reach production."},"id":"zizmor","links":{"html":"https://skillfed.io/packages/zizmor","md":"https://skillfed.io/packages/zizmor.md","pypi":"https://pypi.org/project/zizmor/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-01","license_spdx":null,"license_treatment":"permissive","name":"zizmor","python_support":"supports_current","summary":"Static analysis for GitHub Actions"},"popularity":{"monthly_downloads":5027136,"position":2179,"tier":"top_5000"},"security":{"n_vulnerabilities":0},"version":"1.29.0"}
