Static analysis for GitHub Actions
zizmor is a static analysis tool for GitHub Actions. It can find and fix many
common security issues in typical GitHub Actions CI/CD setups.
This is a third-party/community build, approved by upstream here:
https://github.com/zizmorcore/zizmor/issues/1760
Under strict confinement zizmor reads repositories under your home directory.
Top-level hidden directories (e.g. ~/.local/...) are not covered by the home
interface. For a checkout on removable media:
sudo snap connect zizmor:removable-media