Skip to content

getplumber/plumber

v0.3.87 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 20d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ci-cd compliance pipeline security

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates 👷 CI/CD, 🐛 Bug Fixes, and ♻️ Refactoring across a mixed release.

Full changelog

0.3.87 (2026-07-06)

🐛 Bug Fixes

  • collect: contain local CI-config reads and skip symlinked Dockerfiles (ef9c275)
  • gitlab: harden local include resolution (729e259)

♻️ Refactoring

  • render: sanitize repo-derived text and bound resource use (17ed05e)
  • score: resolve the score endpoint from CLI/env only (0a89351)

👷 CI/CD

  • grype: install pinned grype by checksum, drop scan-action (a275cdf), closes #294
  • pin runtime tool installs to immutable versions (a203b7f)
  • release: pin v0.3.86 refs [skip ci] (101cd21)
  • release: stop persisting credentials in the pin-refs checkout (8f0f261), closes #293
  • scorecard: document the action's mutable-image gap (61c8cdd)

Security Fixes

  • Release: stop persisting credentials in the pin-refs checkout — closes [#293](https://github.com/getplumber/plumber/issues/293)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track getplumber/plumber

Get notified when new releases ship.

Sign up free

About getplumber/plumber

All releases →

Related context

Earlier breaking changes

  • v0.4.0 Runs with nothing scoreable now fail closed (exit 1)
  • v0.4.0 Default artifact name changed to plumber-report
  • v0.4.0 gate no longer exposes 'compliance'; redefines 'passed' as 'score gate met'

Beta — feedback welcome: [email protected]