Skip to content

getplumber/plumber

Pipelines

CI/CD security scanner that checks GitLab CI and GitHub Actions pipelines for risky patterns and vulnerabilities

Go Latest v0.4.16 · 2d ago Security brief →

Features

  • Scans GitLab CI (`.gitlab-ci.yml`) and GitHub Actions workflows locally or via API
  • Centralized configuration via a single `.plumber.yaml` file with provider‑specific policy sections
  • Outputs findings in terminal, JSON, SARIF, GitLab SAST, PBOM, and CycloneDX formats

Recent releases

View all 190 releases →
No immediate action
v0.4.16 New feature

Control output restructuring

No immediate action
v0.4.15 Mixed

Bug fixes + docs + CI

No immediate action
v0.4.13 New feature

CLI fallback to default config

Review required
v0.4.11 Mixed
RCE / SSRF

Controls + GitHub fixes + release pin

No immediate action
v0.4.10 Breaking risk

LogLevel dropped

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
759
Forks
32
Languages
Go Open Policy Agent Shell

Install & Platforms

Install via
brew shell-script binary docker
Platforms
linux macos

Community & Support

Beta — feedback welcome: [email protected]