Audit GitHub Actions for privilege and supply-chain risks with zizmor · git:20260518.471df3d · 2026-05-18 · sha256 641647a7001834a4
Audit GitHub Actions for privilege and supply-chain risks with zizmor git:20260518.471df3dA
Immutable. This exact content is served forever at /api/v1/blob/641647a7001834a4.
--- name: "Audit GitHub Actions for privilege and supply-chain risks with zizmor" slug: "audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor" description: "Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early." github_stars: 4186 verification: "listed" source: "https://github.com/zizmorcore/zizmor" author: "zizmorcore" publisher_type: "organization" category: "Security & Verification" framework: "Multi-Framework" tool_ecosystem: github_repo: "zizmorcore/zizmor" github_stars: 4186 --- # Audit GitHub Actions for privilege and supply-chain risks with zizmor Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early. ## Prerequisites Python 3.9+ or prebuilt zizmor binary, access to the target repository ## Installation Basic usage or getting-started notes: - [detailed usage recipes]. - [detailed usage recipes]: https://docs.zizmor.sh/usage/ - Source: https://github.com/zizmorcore/zizmor - Extracted from upstream docs: https://raw.githubusercontent.com/zizmorcore/zizmor/HEAD/README.md ## Documentation - https://woodruffw.github.io/zizmor/ ## Source - [Agent Skill Exchange](https://agentskillexchange.com/skills/audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor/)