This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalBuild Docker images using Goβ―1.26.5 to resolve the GO-2026-4970 vulnerability.
Why it matters: GO-2026-4970 has a severity score of 90; updating Go to versionβ―1.26.5 eliminates this critical risk in the docker build process.
Summary
AI summaryUpdates π· CI/CD, π Bug Fixes, and 0.3.100 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Build docker images with Go 1.26.5 to clear GO-2026-4970 vulnerability. Build docker images with Go 1.26.5 to clear GO-2026-4970 vulnerability. Source: llm_adapter@2026-07-16 Confidence: high |
β |
Full changelog
0.3.100 (2026-07-09)
π Bug Fixes
- docker: build with Go 1.26.5 to clear GO-2026-4970 (Container Scan) (7d7921d)
π· CI/CD
- add advisory Claude PR review automation (3d2dca6)
- claude: close review-agent secret-exfil surface + dedup/reliability (e0d4057)
- claude: extract poster logic to a unit-tested module (ad39721)
- claude: fix dedup/redaction/sandbox issues from self-review (26ae307)
- claude: fix fingerprint/sanitize/parse bugs + add a relevance bar (c370371)
- claude: fix stateful posting bugs from cursor review (897d3d1)
- claude: harden dedup fence, unanchored-on-failure, multi-line summary (7748dd9)
- claude: post each finding as a resolvable review comment (5f6c56b)
- claude: prompt for whole-system, cross-run review (c079b1a)
- claude: semantic dedup of reworded findings via Haiku (f23ee28)
- claude: stop the review from reviewing its own machinery (ab52069)
- claude: strip planted markers from untrusted finding text (5a3d334)
- claude: use Sonnet for semantic dedup to cut duplicate comments (902f900)
- fix scripts-test to pass the test file explicitly (ffd7b4c)
- release: pin v0.3.99 refs [skip ci] (8f851d5)
Security Fixes
- CVEβGOβ2026β4970 β Docker build updated to GoΒ 1.26.5 to clear Container Scan vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About getplumber/plumber
All releases βBeta — feedback welcome: [email protected]