Skip to content

getplumber/plumber

v0.4.11 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

Published 6d Pipelines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ci-cd compliance pipeline security

Affected surfaces

rce_ssrf

Summary

AI summary

Updates ✨ Features, 🐛 Bug Fixes, and 👷 CI/CD across a mixed release.

Full changelog

0.4.11 (2026-07-20)

✨ Features

  • controls: actionsMustNotExecuteMutableRemoteCode (ISSUE-714/715/716) (4357428), closes #295
  • github: detect mutable exec in Docker-image actions (18be485)

🐛 Bug Fixes

  • control: emit actionsMustNotExecuteMutableRemoteCode findings in JSON output (ceb92e4)
  • github: cut false positives in actionsMustNotExecuteMutableRemoteCode and gate its source fetch on the control being enabled (#299) (46ed6c5)

👷 CI/CD

  • release: pin v0.4.10 refs [skip ci] (a7e5614)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track getplumber/plumber

Get notified when new releases ship.

Sign up free

About getplumber/plumber

All releases →

Related context

Earlier breaking changes

  • v0.4.0 Runs with nothing scoreable now fail closed (exit 1)
  • v0.4.0 Default artifact name changed to plumber-report
  • v0.4.0 gate no longer exposes 'compliance'; redefines 'passed' as 'score gate met'

Beta — feedback welcome: [email protected]