Securing GitHub Actions with William Woodruff episode artwork

EPISODE · May 12, 2025 · 31 MIN

Securing GitHub Actions with William Woodruff

from Open Source Security

William Woodruff discussed his project, Zizmor, a security linter designed to help developers identify and fix vulnerabilities within their GitHub Actions workflows. This tool addresses inherent security risks in GitHub Actions, such as injection vulnerabilities, permission issues, and mutable tags, by providing static analysis and remediation guidance. Fresh off the heels of the tj-actions/changed-files backdoor, this is a great topic with some things everyone can do right away. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-securing-github-actions-william-woodruff/

Episode metadata supplied by the publisher feed · Published May 12, 2025

Embed this episode

Ready to play

Securing GitHub Actions with William Woodruff

0:00 31:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Open Source Security?

This episode is 31 minutes long.

When was this Open Source Security episode published?

This episode was published on May 12, 2025.

Can I download this Open Source Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!