Skip to content

getplumber/plumber

v0.3.23 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2mo Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ci-cd compliance pipeline security

Affected surfaces

rce_ssrf

Summary

AI summary

Fixed template injection in GitHub free‑text controls.

Changes in this release

Bugfix Medium

Scope template injection to free-text GitHub fields.

Scope template injection to free-text GitHub fields.

Source: llm_adapter@2026-05-28

Confidence: low

Full changelog

0.3.23 (2026-05-25)

🐛 Bug Fixes

  • controls: scope template-injection to free-text github fields (fcfbc05), closes #191

Security Fixes

  • Controls: scoped template‑injection vulnerability to GitHub free‑text fields (closes #191)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track getplumber/plumber

Get notified when new releases ship.

Sign up free

About getplumber/plumber

All releases →

Related context

Earlier breaking changes

  • v0.4.0 Runs with nothing scoreable now fail closed (exit 1)
  • v0.4.0 Default artifact name changed to plumber-report
  • v0.4.0 gate no longer exposes 'compliance'; redefines 'passed' as 'score gate met'

Beta — feedback welcome: [email protected]