Audit GitHub Actions for privilege and supply-chain risks with zizmor · git:20260710.62afd0f · 2026-07-10 · sha256 b9db36cf5a661fe7
Audit GitHub Actions for privilege and supply-chain risks with zizmor git:20260710.62afd0fA
Immutable. This exact content is served forever at /api/v1/blob/b9db36cf5a661fe7.
--- name: "Audit GitHub Actions for privilege and supply-chain risks with zizmor" slug: "audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor" description: "Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early." github_stars: 4186 verification: "security_reviewed" source: "https://github.com/zizmorcore/zizmor" author: "zizmorcore" publisher_type: "organization" category: "Security & Verification" framework: "Multi-Framework" tool_ecosystem: github_repo: "zizmorcore/zizmor" github_stars: 4186 --- # Audit GitHub Actions for privilege and supply-chain risks with zizmor Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early. ## Prerequisites Python 3.9+ or prebuilt zizmor binary, access to the target repository ## Installation Basic usage or getting-started notes: - [detailed usage recipes]. - [detailed usage recipes]: https://docs.zizmor.sh/usage/ - Source: https://github.com/zizmorcore/zizmor - Extracted from upstream docs: https://raw.githubusercontent.com/zizmorcore/zizmor/HEAD/README.md ## Documentation - https://woodruffw.github.io/zizmor/ ## Source - [Agent Skill Exchange](https://agentskillexchange.com/skills/audit-github-actions-for-privilege-and-supply-chain-risks-with-zizmor/)