Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

zizmor: New port (v1.4.1) #27783

Merged
merged 1 commit into from
Feb 28, 2025
Merged

Conversation

halostatue
Copy link
Contributor

Description

zizmor is a static analysis tool for GitHub Actions.

It can find many common security issues in typical GitHub Actions CI/CD setups,
including:

  • Template injection vulnerabilities, leading to attacker-controlled code
    execution
  • Accidental credential persistence and leakage
  • Excessive permission scopes and credential grants to runners
  • Impostor commits and confusable git references
  • ...and much more!
Tested on

macOS 15.3.1 24D70 arm64
Xcode 16.2 16C5032a

Verification

Have you

@herbygillot herbygillot merged commit 424a041 into macports:master Feb 28, 2025
3 checks passed
@halostatue halostatue deleted the zizmor-1.4.1 branch February 28, 2025 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

3 participants