Plumber: Open-source scanner of GitLab CI/CD pipelines for compliance gaps
ID: d7517df1-d1e2-5c52-85e7-6023581f78b5
STIX ID: report--d7517df1-d1e2-5c52-85e7-6023581f78b5
Feed Name: Help Net Security
Plumber is an open-source GitLab CI/CD compliance scanner that automates detection of insecure pipeline configurations—such as mutable container tags, untrusted registries, inadequate branch protection, missing templates, and mutable include references. It can run as a CLI or as a CI component, outputs colorized and optional JSON reports, requires a personal access token with read scopes and Maintainer access, and is available under the MPL-2.0 license with prebuilt binaries for major platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
