Files
zizmor will run on GitHub Actions definition files in the following locations:.github/workflows/**/*.yml.github/workflows/**/*.yamlaction.ymlaction.yaml
Configuration
zizmor supports the following config files:zizmor.ymlzizmor.yaml.github/zizmor.yml.github/zizmor.yaml
.coderabbit.yaml file or the CodeRabbit web UI:
- .coderabbit.yaml
- Web UI
.coderabbit.yaml
When we skip zizmor
CodeRabbit will skip running zizmor when:- No GitHub Actions workflow or action files are found in the pull request.
- zizmor is already running in GitHub workflows.
Links
What’s next
actionlint
Lint GitHub Actions workflow files for syntax errors and common misconfigurations.
All supported tools
Browse the complete list of linters, security analyzers, and CI/CD integrations available in CodeRabbit.
Configuration reference
Full reference for all available options, including how to enable, disable, and tune individual tools.