"zizmor is a static analysis tool for GitHub Actions.
It can find many common security issues in typical GitHub Actions CI/CD setups"
https://docs.zizmor.sh/
https://github.com/zizmorcore/zizmor
https://github.com/zizmorcore/zizmor-pre-commit