Skip to content

getplumber/plumber

v0.3.100 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 17d Pipelines
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ci-cd compliance pipeline security

Affected surfaces

deps

ReleasePort's take

Moderate signal
editorial:auto 11d

Build Docker images using Goβ€―1.26.5 to resolve the GO-2026-4970 vulnerability.

Why it matters: GO-2026-4970 has a severity score of 90; updating Go to versionβ€―1.26.5 eliminates this critical risk in the docker build process.

Summary

AI summary

Updates πŸ‘· CI/CD, πŸ› Bug Fixes, and 0.3.100 across a mixed release.

Changes in this release

Security Critical

Build docker images with Go 1.26.5 to clear GO-2026-4970 vulnerability.

Build docker images with Go 1.26.5 to clear GO-2026-4970 vulnerability.

Source: llm_adapter@2026-07-16

Confidence: high

β€”
Full changelog

0.3.100 (2026-07-09)

πŸ› Bug Fixes

  • docker: build with Go 1.26.5 to clear GO-2026-4970 (Container Scan) (7d7921d)

πŸ‘· CI/CD

  • add advisory Claude PR review automation (3d2dca6)
  • claude: close review-agent secret-exfil surface + dedup/reliability (e0d4057)
  • claude: extract poster logic to a unit-tested module (ad39721)
  • claude: fix dedup/redaction/sandbox issues from self-review (26ae307)
  • claude: fix fingerprint/sanitize/parse bugs + add a relevance bar (c370371)
  • claude: fix stateful posting bugs from cursor review (897d3d1)
  • claude: harden dedup fence, unanchored-on-failure, multi-line summary (7748dd9)
  • claude: post each finding as a resolvable review comment (5f6c56b)
  • claude: prompt for whole-system, cross-run review (c079b1a)
  • claude: semantic dedup of reworded findings via Haiku (f23ee28)
  • claude: stop the review from reviewing its own machinery (ab52069)
  • claude: strip planted markers from untrusted finding text (5a3d334)
  • claude: use Sonnet for semantic dedup to cut duplicate comments (902f900)
  • fix scripts-test to pass the test file explicitly (ffd7b4c)
  • release: pin v0.3.99 refs [skip ci] (8f851d5)

Security Fixes

  • CVE‑GO‑2026‑4970 – Docker build updated to GoΒ 1.26.5 to clear Container Scan vulnerability

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track getplumber/plumber

Get notified when new releases ship.

Sign up free

About getplumber/plumber

All releases β†’

Related context

Earlier breaking changes

  • v0.4.0 Runs with nothing scoreable now fail closed (exit 1)
  • v0.4.0 Default artifact name changed to plumber-report
  • v0.4.0 gate no longer exposes 'compliance'; redefines 'passed' as 'score gate met'

Beta — feedback welcome: [email protected]