Skip to content

Bump getplumber/plumber from 0.4.55 to 0.4.63 - #201

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/getplumber/plumber-0.4.62
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/getplumber/plumber-0.4.62

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor

Bumps getplumber/plumber from 0.4.55 to 0.4.63.

Release notes

Sourced from getplumber/plumber's releases.

v0.4.63

0.4.63 (2026-09-14)

✨ Features

  • cmd: push a linked run that evaluated nothing, with the marker the platform records (row 63) (c713d04)
  • control: drive platform-mode collection from the union of the resolved policies (row 62) (f318bcb)

🐛 Bug Fixes

  • cmd: ignore --controls and --skip-controls on a linked run (row 64) (f93ed94)
  • cmd: terminal, exit code and docs follow the policy verdicts on a linked run (row 62) (9b5d4ff)

♻️ Refactoring

  • gitlab: export the multi-document CI parser as ParseGitlabCIConf (row 54) (0795790)

👷 CI/CD

  • release: pin v0.4.62 refs [skip ci] (1840df4)

v0.4.62

0.4.62 (2026-09-12)

🐛 Bug Fixes

  • gitremote: eat every userinfo @ up to the last one before the path (d370cbd)
  • platform: a served empty include list is complete attribution, not unknown (754ab69)
  • platform: use the includes the resolve endpoint serves (dc10a57)

✅ Tests

  • platform: pin the no-attribution branch of the includes served line (9b18a79)
  • platform: pin the wire-level decode of resolve response includes (4e2837d)

👷 CI/CD

  • release: pin v0.4.61 refs [skip ci] (cc366ec)

v0.4.61

0.4.61 (2026-09-12)

... (truncated)

Changelog

Sourced from getplumber/plumber's changelog.

0.5.2 (2026-09-18)

✨ Features

  • identity: recipe version 6, one identity per rule for ISSUE-405, ISSUE-408 and ISSUE-417 (b4f43ed)
  • policies: one finding per rule for missing required templates, components and actions (row 107) (50f6cf7)

👷 CI/CD

  • release: pin v0.5.1 refs [skip ci] (0648860)

0.5.1 (2026-09-17)

🐛 Bug Fixes

  • component: run the plumber job on branch pipelines with an open MR and on plumber/ branches (045fe6f), closes #476

📚 Documentation

👷 CI/CD

  • release: pin v0.5.0 refs [skip ci] (1472696)

0.5.0 (2026-09-17)

⚠ BREAKING CHANGES

  • identity: every ISSUE-406 and ISSUE-409 finding re-keys; a dismissal made under recipe version 4 no longer suppresses them and the platform re-detects the issue once.

Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01FUFtr3m8zC2mVNKVTQvaNz

✨ Features

  • identity: recipe version 5, the override fingerprint keys ISSUE-406 and ISSUE-409 (38c87b0)
  • ir: fingerprint an include's override content from the overridden keys and their values (a8378a5)
  • policies: overridden findings carry the override fingerprint and the overridden jobs (e133aba)

🐛 Bug Fixes

  • ir: the override fingerprint hashes the whole local job block, nested keys included (12fac4c)

... (truncated)

Commits
  • 10837e4 chore(release): 0.4.63 [skip ci]
  • 0795790 refactor(gitlab): export the multi-document CI parser as ParseGitlabCIConf (r...
  • f93ed94 fix(cmd): ignore --controls and --skip-controls on a linked run (row 64)
  • c713d04 feat(cmd): push a linked run that evaluated nothing, with the marker the plat...
  • 9b5d4ff fix(cmd): terminal, exit code and docs follow the policy verdicts on a linked...
  • f318bcb feat(control): drive platform-mode collection from the union of the resolved ...
  • 1840df4 ci(release): pin v0.4.62 refs [skip ci]
  • 8cb2c2d chore(release): 0.4.62 [skip ci]
  • 9b18a79 test(platform): pin the no-attribution branch of the includes served line
  • 754ab69 fix(platform): a served empty include list is complete attribution, not unknown
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 15, 2026
Bumps [getplumber/plumber](https://github.com/getplumber/plumber) from 0.4.55 to 0.4.63.
- [Release notes](https://github.com/getplumber/plumber/releases)
- [Changelog](https://github.com/getplumber/plumber/blob/main/CHANGELOG.md)
- [Commits](getplumber/plumber@6452d3d...10837e4)

---
updated-dependencies:
- dependency-name: getplumber/plumber
  dependency-version: 0.4.62
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump getplumber/plumber from 0.4.55 to 0.4.62 Bump getplumber/plumber from 0.4.55 to 0.4.63 Sep 19, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/getplumber/plumber-0.4.62 branch from 5935de6 to 91818ca Compare September 19, 2026 11:08
@dependabot @github

dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #238.

@dependabot dependabot Bot closed this Sep 22, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/getplumber/plumber-0.4.62 branch September 22, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants