zizmor
brew install zizmor
v1.25.2
MIT
Find security issues and misconfigurations in GitHub Actions workflows.
Why you might care
Analyzes Actions YAML for common vulnerabilities like missing input validation, dangerous permissions, and untrusted code execution. Built in Rust for speed as a single binary. Integrates into CI pipelines to catch config mistakes before they reach production.
4.3k
30-day installs · #672
15.3k
90-day · #643
49.4k
365-day · #696
Build dependencies
Links
- https://docs.zizmor.sh/
- Brew formula source: Formula/z/zizmor.rb
Blurb generated by claude-haiku-4-5 on today.
Raw metadata
{
"aliases": [],
"alternatives": [
"reviewdog",
"actionlint"
],
"build_dependencies": [
"pkgconf",
"rust"
],
"categories": [
"security",
"scanner",
"linter"
],
"caveats": null,
"conflicts_with": [],
"dependencies": [],
"deprecated": 0,
"deprecation_reason": null,
"desc": "Find security issues in GitHub Actions setups",
"disable_reason": null,
"disabled": 0,
"enrichment_fetched_at": "2026-06-20T23:41:01+00:00",
"first_seen": "2026-06-20T23:34:18+00:00",
"full_name": "zizmor",
"github_default_branch": null,
"github_last_commit_at": null,
"github_readme_excerpt": null,
"github_repo": null,
"github_stars": null,
"github_topics": [],
"homepage": "https://docs.zizmor.sh/",
"homepage_og_description": null,
"homepage_og_image": null,
"homepage_title": "Welcome to zizmor\u0027s documentation! - zizmor",
"installs_30d": 4270,
"installs_365d": 49449,
"installs_90d": 15296,
"keg_only": 0,
"keg_only_reason": null,
"last_seen": "2026-06-20T23:34:18+00:00",
"license": "MIT",
"llm_generated_at": "2026-06-20T23:46:18+00:00",
"llm_model": "claude-haiku-4-5",
"name": "zizmor",
"oldnames": [],
"one_liner": "Find security issues and misconfigurations in GitHub Actions workflows.",
"optional_dependencies": [],
"rank_30d": 672,
"rank_365d": 696,
"rank_90d": 643,
"raw_hash": "cf176a5cfd073ed5",
"recommended_dependencies": [],
"revision": 0,
"ruby_source_path": "Formula/z/zizmor.rb",
"tap": "homebrew/core",
"test_dependencies": [],
"uses_from_macos": [],
"version_head": "HEAD",
"version_stable": "1.25.2",
"versioned_formulae": [],
"why_use_this": "Analyzes Actions YAML for common vulnerabilities like missing input validation, dangerous permissions, and untrusted code execution. Built in Rust for speed as a single binary. Integrates into CI pipelines to catch config mistakes before they reach production."
}