NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2094 most downloaded on PyPI
Static analysis for GitHub Actions
Last release 9 days ago
09 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 57 of 57 stable releases
1 version withdrawn
withdrawn after publishing
2 years old
71 releases · first in 2024
One column per month.
This is a small corrective release for some SARIF behavior that changed with v1.2.0.
This release comes with one new audit (bot-conditions), plus a handful of bugfixes and analysis improvements to existing audits.
This release comes with one new audit (bot-conditions), plus a handful of bugfixes and analysis improvements to existing audits.
One bugfix in this release is also a slight behavior change: zizmor now emits SARIF outputs with absolute paths. This should not affect most users, but may make it slightly harder to share SARIF outputs between machines without fully reproducing exact file paths. If this affects you, please let us know!
Fixed a regression where workflows with calls to unpinned reusable workflows would fail to parse
This release comes with one new audit (secrets-inherit), plus a slew of bugfixes and internal refactors that unblock future improvements!
This release comes with one new audit (secrets-inherit), plus a slew of bugfixes and internal refactors that unblock future improvements!
This release comes with one new audit ( secrets-inherit ), plus a slew of bugfixes and internal refactors that unblock future improvements!
The template-injection audit no longer consider github.server_url dangerous ( #412 )
The template-injection audit no longer crashes when evaluating the static-ness of an environment for a uses: step ( #420 )
This is a small quality and bugfix release. Thank you to everybody who helped by reporting and shaking out bugs from our first stable release!
This is a small quality and bugfix release. Thank you to everybody who helped by reporting and shaking out bugs from our first stable release!
GITHUB_PATH,
is more precise, and can produce multiple findings per run block (#391)workflow_call.secrets keys with missing values are now parsed correctly (#388)docker/build-push-action as
a publishing workflow is push: false is explicitly set (#389)github.action_path
to be a potentially dangerous expansion (#402)run: steps with non-trivial
shell: stanzas (#403)Starting with this release, zizmor will use [Semantic Versioning] for its versioning scheme. In short, this means that breaking changes will only happ…
This is the first stable release of zizmor!
Starting with this release, zizmor will use Semantic Versioning for
its versioning scheme. In short, this means that breaking changes will only
happen with a new major version.
This stable release comes with a large number of new features as well as stability commitments for existing features; read more below!
Composite actions (i.e. action.yml where the action is not a Docker
or JavaScript action) are now supported, and are audited by default
when running zizmor on a directory or remote repository (#331)
!!! tip
Composite action discovery and auditing can be disabled by passing
`--collect=workflows-only`. Conversely, workflow discovery and auditing
can be disabled by passing `--collect=actions-only`.
See #350 for the status of each audit's support for analyzing composite actions.
The GitHub host to connect to can now be configured with --gh-hostname
or GH_HOST in the environment (#371)
This can be used to connect to a GitHub Enterprise (GHE) instance
instead of the default github.com instance.
bash and pwsh
inputs (#354)function().foo.bar are now parsed correctly (#340)setup-go were fixed (#343)uses: matching is now case-insensitive where appropriate (#353)'on': foo) are now parsed correctly (#368)<!-- Release notes generated using configuration in .github/release.yml at v0.10.0 -->
<!-- Release notes generated using configuration in .github/release.yml at v0.10.0 -->
Full Changelog: https://github.com/woodruffw/zizmor/compare/v0.9.2...v0.10.0
Full Changelog : https://github.com/zizmorcore/zizmor/compare/v0.9.2...v0.10.0
feat: handle powershell in github-env audit by @woodruffw in #227
feat: template-injection: filter static envs by @woodruffw in #318
feat: add 'primary' locations by @woodruffw in #328
feat: initial cache-poisoning audit by @ubiratansoares in #294
feat: Fix Sarif schema and add rules to Sarif files by @fcasal in #330
fix: template-injection: more safe contexts by @woodruffw in #309
fix: expands_to_static_values considers expressions inside strings by @woodruffw in #317
fix: sarif: add result and kind by @woodruffw in #68
fix: sarif: use ResultKind for kind by @woodruffw in #326
docs: support commits in trophy case by @woodruffw in #303
docs: Fix typo in development.md by @JustusFluegel in #305
@jsoref made their first contribution in #299
@JustusFluegel made their first contribution in #305
@fcasal made their first contribution in #330
<!-- Release notes generated using configuration in .github/release.yml at v0.9.2 -->
<!-- Release notes generated using configuration in .github/release.yml at v0.9.2 -->
Full Changelog: https://github.com/woodruffw/zizmor/compare/v0.9.1...v0.9.2
Full Changelog : https://github.com/zizmorcore/zizmor/compare/v0.9.1...v0.9.2
<!-- Release notes generated using configuration in .github/release.yml at v0.9.1 -->
<!-- Release notes generated using configuration in .github/release.yml at v0.9.1 -->
Full Changelog: https://github.com/woodruffw/zizmor/compare/v0.9.0...v0.9.1
Full Changelog : https://github.com/zizmorcore/zizmor/compare/v0.9.0...v0.9.1
<!-- Release notes generated using configuration in .github/release.yml at v0.9.0 -->
<!-- Release notes generated using configuration in .github/release.yml at v0.9.0 -->
Full Changelog: https://github.com/woodruffw/zizmor/compare/v0.8.0...v0.9.0
Full Changelog : https://github.com/zizmorcore/zizmor/compare/v0.8.0...v0.9.0
refactor: experiment with tracing by @woodruffw in #232
feat: remove --no-progress by @woodruffw in #248
fix: handle non-static env: in job steps by @woodruffw in #246
fix: template-injection: ignore another safe context by @woodruffw in #254
fix: download both .yml and .yaml from repos by @woodruffw in #265
fix: bump annotate-snippets to fix crash by @woodruffw in #264
fix: move artipacked pendantic finding to auditor by @woodruffw in #272
fix: template-injection: ignore runner.temp by @woodruffw in #277
docs: document installing with PyPI by @woodruffw in #242
docs: add a trophy case by @woodruffw in #243
docs: update pre-commit docs to point to new repo by @woodruffw in #247
docs: switch GHA example to uvx by @woodruffw in #255
docs: add template-injection tips by @woodruffw in #259
docs: audits: add another env hacking reference by @woodruffw in #266
docs: Rename "unsecure" to insecure by @szepeviktor in #270
docs: more trophies by @woodruffw in #276
docs: make the trophy case prettier by @woodruffw in #279
feat: remote auditing by @woodruffw in https://github.com/woodruffw/zizmor/pull/230
Full Changelog: https://github.com/woodruffw/zizmor/compare/v0.7.0...v0.8.0
Full Changelog : https://github.com/zizmorcore/zizmor/compare/v0.7.0...v0.8.0
Your coding agent can read these notes before it upgrades. Set up the MCP server →