This release includes 1 security fix for security teams reviewing exposed deployments.
Published 20d
Pipelines
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ci-cd
compliance
pipeline
security
Affected surfaces
auth
rce_ssrf
Summary
AI summaryUpdates 👷 CI/CD, 🐛 Bug Fixes, and ♻️ Refactoring across a mixed release.
Full changelog
0.3.87 (2026-07-06)
🐛 Bug Fixes
- collect: contain local CI-config reads and skip symlinked Dockerfiles (ef9c275)
- gitlab: harden local include resolution (729e259)
♻️ Refactoring
- render: sanitize repo-derived text and bound resource use (17ed05e)
- score: resolve the score endpoint from CLI/env only (0a89351)
👷 CI/CD
- grype: install pinned grype by checksum, drop scan-action (a275cdf), closes #294
- pin runtime tool installs to immutable versions (a203b7f)
- release: pin v0.3.86 refs [skip ci] (101cd21)
- release: stop persisting credentials in the pin-refs checkout (8f0f261), closes #293
- scorecard: document the action's mutable-image gap (61c8cdd)
Security Fixes
- Release: stop persisting credentials in the pin-refs checkout — closes [#293](https://github.com/getplumber/plumber/issues/293)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About getplumber/plumber
All releases →Beta — feedback welcome: [email protected]