-
-
Notifications
You must be signed in to change notification settings - Fork 81
Issues: zizmorcore/zizmor
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Audit idea: use of New feature or request
new-audit
New audits
github.ref
and GITHUB_REF
enhancement
#939
opened Jun 12, 2025 by
woodruffw
Feature: New feature or request
use-trusted-publishing
should check for disabled attestations
enhancement
#938
opened Jun 12, 2025 by
woodruffw
Audit idea: TOCTOU PR/branch checks
enhancement
New feature or request
help wanted
Extra attention is needed
new-audit
New audits
#935
opened Jun 11, 2025 by
woodruffw
Feature: detect general correctness errors
enhancement
New feature or request
triage
Issue is being triaged
#931
opened Jun 10, 2025 by
andrewbanchich
2 tasks done
Evaluate saphyr for YAML operations
long-term
refactor
Refactoring tasks
#930
opened Jun 10, 2025 by
woodruffw
Feature: detect invisible unicode characters
enhancement
New feature or request
help wanted
Extra attention is needed
new-audit
New audits
#914
opened Jun 7, 2025 by
andrewbanchich
2 tasks done
[META] Fix mode features
meta
Roadmap/meta tracking issues
#876
opened May 30, 2025 by
woodruffw
2 of 11 tasks
[BUG] Something isn't working
cli
zizmor --completions <SHELL>
fails if another flag is implicitly activated via the environment
bug
#864
opened May 28, 2025 by
woodruffw
New audit: old(er) runs-on
enhancement
New feature or request
good first issue
Good for newcomers
new-audit
New audits
#827
opened May 19, 2025 by
woodruffw
New audit: comments next to explicit permissions
enhancement
New feature or request
good first issue
Good for newcomers
new-audit
New audits
#819
opened May 18, 2025 by
woodruffw
Feature: A way to collect workflows only in Configuration functionality
enhancement
New feature or request
<root>/.github/workflows/
config
#784
opened May 12, 2025 by
iainlane
2 tasks done
Feature: New feature or request
false-negative
cache-poisoning
: treat docker/build-build-action
as a potential cache source
enhancement
#774
opened May 9, 2025 by
woodruffw
Feature: reduce GitHub REST API usage in favor of clones?
performance
#764
opened May 8, 2025 by
woodruffw
Feature: wrong value in ternary pattern
enhancement
New feature or request
help wanted
Extra attention is needed
new-audit
New audits
#746
opened May 5, 2025 by
daeho-ro
2 tasks done
Feature: detect no-op conditions
enhancement
New feature or request
help wanted
Extra attention is needed
#742
opened May 3, 2025 by
woodruffw
Feature: New feature or request
unpinned-images
could discover docker pull ...
patterns in run:
clauses
enhancement
#738
opened May 2, 2025 by
woodruffw
Feature: policies for New feature or request
unpinned-images
enhancement
#737
opened May 2, 2025 by
woodruffw
[BUG]: impostor-commit audit tries lookup on wrong github instance
bug
Something isn't working
ghes
GitHub Enterprise Server issues
#735
opened May 2, 2025 by
dankress
2 tasks done
New audit: Dependabot privilege escalation
discussion
enhancement
New feature or request
new-audit
New audits
#730
opened Apr 30, 2025 by
Marcono1234
New audit: Caching sensitive files
enhancement
New feature or request
new-audit
New audits
#723
opened Apr 30, 2025 by
Marcono1234
Feature: Support enabling / disabling audits
enhancement
New feature or request
#714
opened Apr 29, 2025 by
Marcono1234
2 tasks done
New audit: "YOLO" binaries
enhancement
New feature or request
new-audit
New audits
#711
opened Apr 29, 2025 by
woodruffw
Previous Next
ProTip!
Find all open issues with in progress development work with linked:pr.