Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 22, 2026 (about 3 months ago).

distribution · May 22, 2026

Trail of Bits Hardens zizmor GitHub Actions Analyzer Following LiteLLM Supply Chain Incident

Share the canonical public link.

Share as image

Trail of Bits released updates to zizmor on May 22, 2026, adding full YAML anchor support and fixing four parsing bugs after testing against 41,253 real GitHub Actions workflows from 6,612 repositories. The work directly references the March 2026 Trivy GitHub Action compromise that enabled TeamPCP to backdoor LiteLLM on PyPI via stolen credentials. Updates included 15 merged pull requests, integration tests for anchors, and alignment of the expression evaluator with GitHub’s Known Answer Tests. Zizmor now catches more workflow misconfigurations to prevent similar supply-chain attacks across open-source projects including LiteLLM.

Below validation threshold — auto-passed without scoring

Supporting evidence