distribution · May 22, 2026
Trail of Bits Hardens zizmor GitHub Actions Analyzer Following LiteLLM Supply Chain Incident
Share the canonical public link.
Trail of Bits released updates to zizmor on May 22, 2026, adding full YAML anchor support and fixing four parsing bugs after testing against 41,253 real GitHub Actions workflows from 6,612 repositories. The work directly references the March 2026 Trivy GitHub Action compromise that enabled TeamPCP to backdoor LiteLLM on PyPI via stolen credentials. Updates included 15 merged pull requests, integration tests for anchors, and alignment of the expression evaluator with GitHub’s Known Answer Tests. Zizmor now catches more workflow misconfigurations to prevent similar supply-chain attacks across open-source projects including LiteLLM.