zizmorcore/zizmor
github.com原文 ↗
zizmor 是 GitHub Actions 的静态分析工具,目标是发现 CI/CD 配置里的安全问题。README 列出的检测面包括 template injection、credential persistence/leakage、过宽 permission scopes、runner credential grants、impostor commits 和 confusable `git` references;它把 Actions 安全审计前移到代码扫描阶段。
–浏览
评论 · Comments