DiscoverOpen Source SecuritySecuring GitHub Actions with William Woodruff
Securing GitHub Actions with William Woodruff

Securing GitHub Actions with William Woodruff

Update: 2025-05-12
Share

Description

William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guidance. Fresh off the heels of the tj-actions/changed-files backdoor, this is a great topic with some things everyone can do right away.

The show notes and blog post for this episode can be found at
https://opensourcesecurity.io/2025/2025-05-securing-github-actions-william-woodruff/

Comments 
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Securing GitHub Actions with William Woodruff

Securing GitHub Actions with William Woodruff