Add Plumber CI/CD security scanning - #3271
Open
thomasboni wants to merge 1 commit into
Open
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
thomasboni
force-pushed
the
add-plumber
branch
2 times, most recently
from
July 1, 2026 12:07
668e301 to
1ed4cdb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Salut Aurélie 👋
@rverchere m'a dit que ça t'irait que je te propose d'ajouter plumber ici 🙂
Plumber, c'est un scanner de sécurité pour pipelines CI/CD (actions non pinnées, triggers dangereux, injection de scripts, etc.).
Cette PR ajoute :
.github/workflows/plumber.ymlqui lance Plumber sur les push & PRs.plumber.yaml, le ruleset par défaut (tu peux désactiver/ajuster ce que tu veux)score-push: true. Ça publie l'artefact de résultat de l'analyse (le JSON complet avec le grade, les métriques et le détail des contrôles) surscore.getplumber.io, et le nom du repo + son score deviennent publics. T'as un exemple de ce qui est poussé ici : https://getplumber.io/docs/plumber-score. Aucun souci si tu préfères pas publier : dis-le moi et j'enlève le badge + les lignesscore-push/id-token, le scan tourne pareil sans rien publier.Pas de pression pour merger, dis-moi ce que t'en penses 🙏