lfreleng-actions/Zizmor security audit

Audit GitHub Actions workflows with the zizmor static analyser.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
personazizmor persona: regular, pedantic, or auditor.noauditor
min-severityLowest severity reported: unknown, informational, low, medium, high.noinformational
min-confidenceLowest confidence reported: low, medium, or high. Empty audits all confidences.no""
working-directoryPath within the workspace to audit.no.
zizmor-versionOverride the bundled pin with an explicit tag (e.g. v1.25.2).no""
extra-argsAdditional raw arguments appended to the zizmor call.no""
upload-sarifUpload the SARIF to code scanning from within this action.nofalse
summary-repositoryowner/repo label for step-summary links; defaults to the repository running the workflow. Set when the workspace holds a checkout of a different repository. Applies only together with summary-sha: a partial or malformed pair is ignored with a warning.no""
summary-shaCommit SHA (7-40 hex digits) for step-summary links; defaults to the workflow commit. Applies only together with summary-repository: a partial or malformed pair is ignored with a warning.no""
namedescription
sarif-fileAbsolute path to the generated SARIF file.