Skip to content

getplumber/plumber

v0.3.89 Bugfix

This release fixes issues for SREs watching stability and regressions.

Published 19d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ci-cd compliance pipeline security

Summary

AI summary

Updates 🔧 Chores, 🐛 Bug Fixes, and 👷 CI/CD across a mixed release.

Full changelog

0.3.89 (2026-07-07)

🐛 Bug Fixes

  • config: warn when a present local CI config is unreadable (a099337)
  • github: keep scanning repo artifacts when the workflows dir is rejected (2a0fcb1)

🔧 Chores

  • config: bound configuration and CI-config file reads (aff1f01)
  • github: harden workflow and dependabot file collection (7ccfa4c)
  • mrcomment: harden comment text escaping (52b1985)
  • render: harden degraded-reason and CI-error output (2d785b8)
  • render: harden verification-warning output (8179ff6)

👷 CI/CD

  • release: pin v0.3.88 refs [skip ci] (beb8d19)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track getplumber/plumber

Get notified when new releases ship.

Sign up free

About getplumber/plumber

All releases →

Related context

Earlier breaking changes

  • v0.4.0 Runs with nothing scoreable now fail closed (exit 1)
  • v0.4.0 Default artifact name changed to plumber-report
  • v0.4.0 gate no longer exposes 'compliance'; redefines 'passed' as 'score gate met'

Beta — feedback welcome: [email protected]