GeistHaus
log in · sign up

Audit Rules🔗

docs.zizmor.sh

Audit rules, examples, and remediations.

15 pages link to this URL
Release v1.13.0 · zizmorcore/zizmor

New Features 🌈🔗 New audit: undocumented-permissions detects explicit permission grants that lack an explanatory comment (#1131) Many thanks to @johnbillion for proposing and implementing this aud...

1 inbound link object en repository:844670429
Release v1.10.0 · zizmorcore/zizmor

This is a huge new release, with multiple new features, enhancements, and bugfixes! New Features 🌈🔗 New audit: anonymous-definition detects unnamed workflows and actions. Definitions without a na...

1 inbound link object en repository:844670429
Release v1.12.0 · zizmorcore/zizmor

New Features 🌈🔗 New audit: unsound-condition detects if: conditions that inadvertently always evaluate to true (#1053) Enhancements 🌱🔗 The cache-poisoning audit now supports auto-fixes for many ...

1 inbound link object en repository:844670429
Defense in Depth: A Practical Guide to Python Supply Chain Security

A comprehensive guide to securing your Python dependencies from ingestion to deployment, covering linting, pinning, vulnerability scanning, SBOMs, and attestations

6 inbound links article en posts pythonsecuritydependenciessupply-chainsbompypipip