zizmorcore/zizmor
78.4
Strong · 29 September 2026
34.6k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Zizmor is a command-line security auditing tool for GitHub Actions workflows, composite actions, Dependabot configurations, and pre-commit hooks. It parses and analyzes these YAML-based definitions to detect security vulnerabilities, such as template injections and excessive permissions, while supporting auto-fixes and multiple output formats like SARIF. The system leverages custom Rust crates for precise YAML parsing, expression evaluation, and format-preserving modifications to ensure accurate and actionable security findings.
How it got here
2024–2025 — Initial release and workspace restructuring
32 changes.
This period covers the initialization of the zizmor project, including repository setup, Rust 2024 migration, and restructuring into a multi-crate workspace. It features the initial v0.1.0 release of the GitHub Actions security auditing tool, introducing core data models, audit rules, and output formatting capabilities.
2026 — matrix expansion and dependency reduction
4 changes.
The project enhanced workflow analysis by implementing matrix expression expansion to correctly audit self-hosted runners and unpinned images. It also introduced a new crate for parsing pre-commit configurations and replaced the external serde-sarif dependency with internal SARIF models to reduce external dependencies.
Features
Configurable audit rules with severity remapping and JSON schema support
Users can now customize zizmor's behavior via a configuration file (e.g., \.github/zizmor.yml\) by disabling specific audits, ignoring findings at precise file/line/column locations, and remapping audit severities (e.g., changing a High finding to Low). This location introduces the core configuration data models, parsing logic, and error handling for these rules, while also providing a generated JSON Schema to validate configuration files and support IDE autocomplete.
crates/zizmor/src/config · high confidence
Initial Dependabot v2 configuration model support
This change introduces the foundational data models for parsing and validating Dependabot v2 configuration files (\dependabot.yml\). It defines the structure for the main configuration, including support for multi-ecosystem update groups, various registry types (such as Cargo, Docker, Npm, and Goproxy), and update directives with features like cooldown settings, directory targeting, and pull request limits. This enables the application to correctly interpret complex Dependabot configurations.
crates/github-actions-models/src/dependabot · high confidence
Introduce GitHub Actions data models crate
This change adds a new \github-actions-models\ crate that provides Rust data structures for parsing and representing GitHub Actions definitions. It includes models for action metadata (inputs, outputs, runs), composite action steps, and common utilities like environment variable handling and permission scopes, enabling the rest of the application to deserialize and analyze GitHub Actions workflows and action definitions.
crates/github-actions-models/src · high confidence
Introduce comprehensive GitHub Actions workflow data models
This change adds the core data models for parsing and validating GitHub Actions workflow definitions within the \github-actions-models\ crate. It introduces structured types for workflow triggers (including the new \image\_version\ event and support for scalar or vector event bodies), job definitions (supporting \runs-on\ groups, environments, concurrency, and timeout minutes as floats), and step definitions (including new \wait\, \wait\_all\, \cancel\, and \parallel\ step types for background and parallel execution). The models also handle workflow-level configuration such as permissions, environment variables, and defaults, enabling more accurate analysis of workflow syntax and behavior.
crates/github-actions-models/src/workflow · high confidence
Introduce pre-commit-models crate for parsing pre-commit configurations
The new \pre-commit-models\ crate provides Rust data models for parsing \.pre-commit-config.yml\ and \.pre-commit-hooks.yml\ files. It supports standard pre-commit fields and includes extensions for the \prek\ tool, such as \builtin\ repository types, glob-based file patterns, and language version preferences. This enables the application to accurately validate and analyze pre-commit setups.
crates/pre-commit-models · high confidence
Introduce subfeature crate for YAML fragment matching
Added the \subfeature\ crate, which provides APIs for creating and matching subfeatures (syntactically relevant extracts of a YAML document) against parent features. This includes the \Fragment\ type for matching raw strings or regular expressions (handling whitespace malleability) and the \Subfeature\ struct for locating these fragments within a larger YAML feature using byte spans.
crates/subfeature · high confidence
Introduce symbolic location model with subfeature support
The finding module now uses a new \SymbolicLocation\ type to represent locations via a route of keys and indices, rather than concrete text spans. This allows findings to reference specific parts of a YAML document (such as subfeatures or key-only nodes) and supports distinguishing between primary, related, and hidden locations for better output formatting in tools like SARIF. Users will see more precise and structured location information in audit results, with the ability to link annotations to specific document features.
crates/zizmor/src/finding · high confidence
Introduce tree-sitter-iter for ergonomic CST traversal
Added the \tree-sitter-iter\ crate, which provides a \TreeIter\ struct to iterate over tree-sitter Concrete Syntax Tree (CST) nodes in pre-order. This offers a more ergonomic \Iterator\ interface compared to manually using \TreeCursor\, while maintaining equivalent space and time performance. The implementation includes tests verifying that the iterator visits the same number of nodes as the standard \descendant\_count\ method.
crates/tree-sitter-iter · high confidence
Introduce yamlpatch crate for format-preserving YAML modifications
The new \crates/yamlpatch\ library provides a set of operations to modify YAML documents while preserving their original formatting, comments, and style. It supports patching specific features via routes, including rewriting string fragments, adding or replacing comments, merging mappings, appending to sequences, and removing keys. The crate handles various YAML styles such as block and flow mappings/sequences, as well as literal and folded scalars, ensuring that structural changes do not disrupt the document's visual layout.
crates/yamlpatch/src · high confidence
Introduces a new input registry for managing diverse GitHub Actions inputs
The tool now features a dedicated input registry (input.rs) that centralizes the collection and validation of various input types, including workflows, actions, Dependabot configurations, and pre-commit hooks. This change introduces structured error handling for collection issues (such as invalid YAML, schema mismatches, or remote fetch failures) and supports grouping inputs, which allows for more granular configuration and error reporting when auditing GitHub repositories.
crates/zizmor/src/registry · high confidence
Introduces auto-fix capability and refactors output formatting
This change introduces a new auto-fix capability, adding a \fix.rs\ module that applies fixes to source files based on a specified mode (safe, unsafe-only, or all) and reports a summary of applied and failed fixes. It also refactors the output subsystem by introducing a dedicated \github.rs\ module for generating GitHub Actions workflow commands, restructuring the SARIF output to use code flows for better visualization of location chains, and updating the plain text output to display fix disposition counts. These changes are implemented within the \crates/zizmor/src/output\ directory.
crates/zizmor/src/output · high confidence
Introduction of YAML path routing with anchor and alias support
The \crates/yamlpath/src\ module has been added to provide format-preserving YAML path routes that capture exact parse spans and comments, distinct from generic object routing tools like JSONPath. This implementation introduces support for YAML anchors and aliases, including specific fixes for handling anchors within flow sequences and mappings, as well as improvements to error reporting for invalid inputs.
crates/yamlpath/src · high confidence
New audit for workflows and jobs without names
Added the \anonymous-definition\ audit rule, which flags workflows and jobs that lack a \name\ field. This helps improve discoverability and clarity in the GitHub UI by encouraging users to provide descriptive names for their workflow definitions.
crates/zizmor/src/audit · high confidence
New data models for GitHub Actions, Dependabot, and pre-commit configurations
The \crates/zizmor/src/models\ directory now contains dedicated Rust structs and traits for modeling GitHub Actions workflows and composite actions, Dependabot configuration files, and pre-commit configuration files. These models provide higher-level APIs over the underlying YAML structures, enabling zizmor to validate inputs, track symbolic locations for findings, and parse repository references and version constraints used in \uses:\ clauses.
crates/zizmor/src/models · high confidence
New support scripts for maintaining audit data and test fixtures
Added a suite of support scripts to automate the maintenance of internal data sources and test suites. \archive-release.sh\ handles packaging release binaries into archives for distribution. \archived-repos.py\ merges curated lists of archived GitHub Actions and pre-commit hooks into a single sorted dataset used by the \archived-uses\ audit. \codeql-injection-sinks.py\ fetches and processes CodeQL models to identify known code-injection sinks in actions. \fetch-schemas.py\ downloads and dereferences JSON schemas for GitHub workflows and other formats. \sync-expression-tests.py\ updates expression test data from the upstream \actions/languageservices\ repository. These scripts ensure the tool's data remains current and tests stay in sync with upstream specifications.
support · high confidence
Repository initialization with documentation, build tooling, and licensing
The repository is initialized with core project files including the MIT License, a Dockerfile for containerized builds, and a Makefile for managing documentation and schema generation. The documentation site is configured via mkdocs.yml, and the Rust toolchain is pinned to version 1.97.0. Additionally, contributor guidelines are established through CONTRIBUTING.md and AGENTS.md, which enforces an AI policy for contributions, while the Python dependency graph is recorded in uv.lock.
(repo-wide) · high confidence
Support for GitHub Actions expressions in YAML models
The \github-actions-models\ crate now includes support for parsing GitHub Actions expressions (e.g., \${{ foo }}\) within YAML configurations. A new \ExplicitExpr\ type validates and stores these expressions, while the \LoE\ (Literal or Expression) generic enum allows fields to accept either a standard literal value or an expression, automatically attempting to parse as an expression first. This enables more accurate modeling of GitHub Actions workflow files where values can be dynamic expressions rather than static strings.
crates/github-actions-models/src/common · high confidence
zizmor v0.1.0: Initial release of the GitHub Actions security auditing tool
This entry marks the initial release of zizmor, a CLI tool for auditing GitHub Actions workflows and composite actions for security issues. The release introduces a comprehensive set of audit rules (such as template-injection, impersonation, and use-trusted-publishing), a structured finding model with severity and confidence levels, and multiple output formats including human-readable diagnostics and JSON. It supports auditing local files, directories, and remote GitHub repositories, with features like automatic fix application (experimental), LSP integration for IDE support, and configuration via YAML files.
crates/zizmor/src · high confidence
Removals
Removal of initial CLI prototype and core data models
The initial prototype implementation for the CLI tool has been removed, including the \src/main.rs\ entry point, the \src/models.rs\ workflow data structures, and the \src/finding.rs\ finding definitions. This change eliminates the original single-file auditing capability that only supported the 'artipacked' check and basic JSON output, clearing the codebase for the expanded audit framework and multi-format output features introduced in subsequent commits.
src · high confidence
Removal of the artipacked audit check
The \artipacked\ audit module has been removed from the codebase. This means the tool no longer detects workflows where \actions/checkout\ persists credentials followed by \actions/upload-artifact\ steps that could expose them. Users will no longer receive findings for this specific credential-persistence pattern.
src/audit · high confidence
Behavioural changes
Build script generates static data indexes for audits
The zizmor build script now compiles static data files into optimized indexes at build time. It generates an FST map from \data/context-capabilities.csv\ to support context pattern matching, copies \data/codeql-injection-sinks.json\ for CodeQL injection analysis, and creates FST sets from \data/archived-repos.txt\ and \data/github-hosted-runners.txt\ to back the new archived-repos and GitHub-hosted-runners audits.
crates/zizmor · high confidence
Replaced Pest parser with a hand-written recursive-descent parser for GitHub Actions expressions
The \github-actions-expressions\ crate now uses a custom recursive-descent parser and lexer instead of the previous Pest-based parser. This change introduces a strict recursion budget (50 levels) to prevent stack overflow on deeply nested expressions, enforces case-insensitive matching for function names and identifiers, and adds precise source-span tracking for all tokens and expressions. Users will see more accurate error reporting with byte offsets, stricter validation of function argument counts (arity), and improved handling of edge cases like NaN and Infinity in numeric literals.
crates/github-actions-expressions/src · high confidence
Support for matrix expressions in runner and image configurations
The workflow model now handles matrix expressions within \runs-on\ clauses and container image definitions. A new \matrix.rs\ module expands strategy matrices into concrete values, tracking static and indirect expansions (including those in \include\/\exclude\ blocks). The \runners.rs\ module uses this expansion logic to determine if a job's runner is self-hosted, even when the \runs-on\ label or group is derived from a matrix, and flags indeterminate cases where expressions prevent static resolution. This allows the tool to correctly audit self-hosted runner usage and unpinned images that depend on matrix variables.
crates/zizmor/src/models/workflow · high confidence
Updated static audit data for GitHub Actions analysis
The \crates/zizmor/data\ directory has been populated with new static data files that enhance the tool's ability to analyze GitHub Actions workflows. \archived-repos.txt\ lists known archived actions to flag usage of unmaintained code, while \popular-actions.txt\ identifies widely used actions for prioritization. \codeql-injection-sinks.json\ maps specific actions to their code injection sink parameters, and \context-capabilities.csv\ defines the mutability and source of various GitHub context properties. Additionally, \github-hosted-runners.txt\ provides an updated list of supported runner images, ensuring accurate detection of runner-specific configurations.
crates/zizmor/data · high confidence
Test coverage
Add Known-Answer Tests for GitHub Actions Expressions; Added benchmarking suite for zizmor performance; Added e2e crater and JSON v1 output snapshots; Added end-to-end tests for YAML anchors, parallel steps, and JSON v1 output; Added integration tests for YAML path queries; Added tests for GitHub Actions model deserialization; Added unit tests for YAML patch serialization and style detection; Integration test suite for CLI, configuration, and end-to-end workflows; Integration tests added for multiple audit rules; Updated integration test snapshots for e2e audit results and input validation.
Dependencies
Replace external serde-sarif dependency with minimal internal SARIF models
The zizmor-sarif crate no longer depends on the external \serde-sarif\ library. Instead, it now ships its own minimal, zizmor-specific data models for SARIF 2.1.0, covering only the fields required for zizmor's output. This change reduces external dependencies and allows for a more tailored serialization of SARIF results.
crates/zizmor-sarif · high confidence
zizmor 1.30.1: Rust 2024 migration and workspace restructuring
zizmor has been upgraded to version 1.30.1, migrating the codebase to the Rust 2024 edition and raising the minimum supported Rust version (MSRV) to 1.97.0. The project has been restructured into a multi-crate workspace, extracting core components such as \github-actions-expressions\, \github-actions-models\, \yamlpath\, and \yamlpatch\ into dedicated crates. This release also updates key dependencies, including \clap\ to 4.6.1, \serde\ to 1.0.228, and \reqwest\ to 0.13, while replacing \serde\_yaml\ with \yaml\_serde\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 80 → 78 (-1.4)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 87 → 87 (+0.3)
- Architecture 97 → 97 (+0.1)
- Maturity 71 → 71 (+0.1)
- Readiness 83 → 78 (-5.0)
- Security 92 → 88 (-3.6)
- Domain Modelling 100 → 100 (+0.0)
- Performance 94 (new)
Resolved (18)
- Documentation: no installation or build instructions (docs/installation.md)
- Documentation: no project overview (docs/index.md)
- Duplicated block (11 lines × 2) (crates/zizmor/src/audit/github_env.rs)
- Duplicated block (12–13 lines × 3) (crates/zizmor/src/audit/adhoc_packages.rs)
- Duplicated block (13 lines × 2) (crates/zizmor/src/audit/dangerous_triggers.rs)
- Events::count (cognitive 27) (crates/github-actions-models/src/workflow/event.rs)
- Events::count (cyclomatic 28) (crates/github-actions-models/src/workflow/event.rs)
- Hotspot: crates/zizmor/src/audit/artipacked.rs (crates/zizmor/src/audit/artipacked.rs)
- Hotspot: crates/zizmor/src/audit/bot_conditions.rs (crates/zizmor/src/audit/bot_conditions.rs)
- Hotspot: crates/zizmor/src/audit/template_injection.rs (crates/zizmor/src/audit/template_injection.rs)
- Hotspot: crates/zizmor/src/audit/use_trusted_publishing.rs (crates/zizmor/src/audit/use_trusted_publishing.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (crates/zizmor/src/audit/obfuscation.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/zizmor/src/models/action.rs)
- TodoComment (crates/github-actions-models/src/workflow/event.rs)
- TodoComment (crates/github-actions-models/src/workflow/event.rs)
- TodoComment (crates/github-actions-models/src/workflow/event.rs)
- TodoComment (crates/pre-commit-models/src/common.rs)
- TodoComment (crates/zizmor/src/registry/input.rs)
New (19)
- Ambiguous naming. 'key_only' is not a standard term for what this operation does (likely retrieving just the key part of a route or checking key existence). It differs from query_pretty/query_exact in naming style.
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no project overview (docs/usage.md)
- Duplicated block (11 lines × 2) (crates/zizmor/src/audit/github_env.rs)
- Duplicated block (11–12 lines × 3) (crates/zizmor/src/audit/adhoc_packages.rs)
- End-of-life runtime: Rust 1.97
- Inconsistent naming with yamlpatch module. The Document type uses query_pretty and query_exact, while the yamlpatch module uses route_to_feature_pretty and route_to_feature_exact. The verb 'query' vs 'route_to_feature' is inconsistent for the same conceptual operation (retrieving content at a route).
- Inverted test pyramid
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (crates/zizmor/src/audit/obfuscation.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/zizmor/src/models/action.rs)
- Off the main sequence: subfeature
- Off the main sequence: tree-sitter-iter
- Redundant naming convention for similar operations. 'pretty' and 'exact' are vague qualifiers that don't clearly distinguish the semantic difference (likely whitespace/formatting preservation vs. strict structural matching).
- TodoComment (crates/github-actions-models/src/workflow/event.rs)
- TodoComment (crates/github-actions-models/src/workflow/event.rs)
- TodoComment (crates/pre-commit-models/src/common.rs)
- TodoComment (crates/pre-commit-models/src/common.rs)
- TodoComment (crates/zizmor/src/audit/cache_poisoning.rs)
Changes since last survey
- 25 commits — 23 feature/other, 2 fixes
By area
- crates/zizmor — 8 commits
- (root) — 6 commits
- .github/workflows — 4 commits
- docs/snippets — 4 commits
- crates/github-actions-models — 2 commits
- crates/pre-commit-models — 1 commit
Notable commits
- fix: Fix release notes (#2391)
- fix: fix(adhoc-packages): match add in the subcommand position for pnpm/yarn (#2386)
- change: Add image_version trigger, clean up triggers in general (#2397)
- change: Bump trophies (#2419)
- change: Handle prek's extension to (default_)language_version (#2413)
- change: Improve sponsor table rendering (#2408)
- change: Improve symbolic locations for triggers (#2402)
- change: Refactor Trigger (#2414)
- change: Update sponsors (#2392)
- change: Update sponsors (#2407)
- change: Update sponsors (#2410)
- change: chore(deps): bump actions/deploy-pages in the github-actions group (#2387)
- change: chore(deps): bump the cargo group across 1 directory with 7 updates (#2369)
- change: chore(deps): bump the cargo group with 3 updates (#2399)
- change: chore(deps): bump the cargo group with 3 updates (#2415)
- change: chore(deps): bump the github-actions group with 2 updates (#2416)
- change: chore(deps): bump the github-actions group with 3 updates (#2400)
- change: chore(deps-dev): bump the uv group with 2 updates (#2417)
- change: chore(deps-dev): bump zensical from 0.0.57 to 0.0.59 in the uv group (#2388)
- change: chore(deps-dev): bump zensical from 0.0.59 to 0.0.62 in the uv group (#2401)
- …and 5 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
zizmorcore/zizmor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9a0b330c8c5847ffe8d45ca3820b118deece8c68 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.