Skip to content
getplumber/plumber
Pipelines
CI/CD security scanner that checks GitLab CI and GitHub Actions pipelines for risky patterns and vulnerabilities
Go
·
Latest v0.4.16 · 2d ago
Security brief →
Features
-
Scans GitLab CI (`.gitlab-ci.yml`) and GitHub Actions workflows locally or via API
-
Centralized configuration via a single `.plumber.yaml` file with provider‑specific policy sections
-
Outputs findings in terminal, JSON, SARIF, GitLab SAST, PBOM, and CycloneDX formats
No immediate action
v0.4.16
New feature
·
Control output restructuring
No immediate action
v0.4.15
Mixed
·
Bug fixes + docs + CI
No immediate action
v0.4.13
New feature
·
CLI fallback to default config
Review required
v0.4.11
Mixed
·
RCE / SSRF
Controls + GitHub fixes + release pin
No immediate action
v0.4.10
Breaking risk
·
LogLevel dropped
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Go
·
Open Policy Agent
·
Shell
View on GitHub
Documentation
Install & Platforms
Install via
brew
shell-script
binary
docker
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open