pre-commit: add `zizmor` a static analysis tool for GitHub Actions
Open
type:enhancement
- Dominant language
- Java
- Stars
- 3.1k
- Forks
- 1.4k
- Avg merge
- 6d 19h
- Merged PRs (30d)
- 32
Description
"zizmor is a static analysis tool for GitHub Actions.
It can find many common security issues in typical GitHub Actions CI/CD setups"
https://docs.zizmor.sh/
https://github.com/zizmorcore/zizmor
https://github.com/zizmorcore/zizmor-pre-commit
Contributor guide
Research direction
Start with the repository's pre-commit configuration and the linked zizmor-pre-commit documentation, then review the linked zizmor documentation for the intended hook setup. Done means zizmor is registered for the repository's GitHub Actions checks and the existing pre-commit checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security, tooling
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100