Skip to content

Bump getplumber/plumber from 0.4.39 to 0.4.44 - #1057

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-github_actions-getplumber-plumber-0.4.44
Open

Bump getplumber/plumber from 0.4.39 to 0.4.44#1057
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-github_actions-getplumber-plumber-0.4.44

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps getplumber/plumber from 0.4.39 to 0.4.44.

Release notes

Sourced from getplumber/plumber's releases.

v0.4.44

0.4.44 (2026-08-26)

✨ Features

  • controls: add projectMustHaveSecurityPolicySource (ISSUE-601, GitLab Ultimate) and renumber workflowsMustHaveExplicitName to ISSUE-422 for site parity (9d62204)

🐛 Bug Fixes

  • controls: address review on the security policy source control (0217d76)

📚 Documentation

  • controls: update controls doc to make it more precise (1eaca39)

👷 CI/CD

  • release: pin v0.4.43 refs [skip ci] (cfb0484)

v0.4.43

0.4.43 (2026-08-26)

✨ Features

  • controls: add mergeRequestSettingsMustBeCompliant (ISSUE-506) with a conditional Premium/Ultimate caveat for merge-train and merged-pipeline expectations (6345dc4)
  • controls: make ISSUE-503 approval-settings findings read as current-vs-expected and add a Premium/Ultimate tier caveat when no protections are in effect (deacbfb)

🐛 Bug Fixes

  • controls: address review on the MR approval/settings controls (a70ef57)

👷 CI/CD

  • release: pin v0.4.42 refs [skip ci] (4d247c2)

v0.4.42

0.4.42 (2026-08-25)

✨ Features

  • controls: Add MR approval rules controls (a2dfb69), closes #412

... (truncated)

Changelog

Sourced from getplumber/plumber's changelog.

0.4.51 (2026-09-01)

✨ Features

  • catalog: export human-readable control names and categories (#440) (c50e9c7)

✅ Tests

  • platform: assert display metadata on the decoded push body for all three finding branches (2dbf0c5)
  • platform: pin the review-flagged guards from the platform-mode audit (8261477), closes #431

👷 CI/CD

  • release: pin v0.4.50 refs [skip ci] (39b2b67)

0.4.50 (2026-08-31)

✨ Features

  • platform: export include job attribution and consume includes[].jobs (619949c)
  • platform: fetch policies and collected data from the platform (9e3fb7e)
  • platform: fire the resolve request at setup and collect it at first use (97656cb)

🐛 Bug Fixes

  • cmd: compare the checkout remote to --gitlab-url ignoring the scheme (bdc398e)
  • gitlab: a platform cache miss is not an authoritative empty variables listing (4c6f96e)
  • gitlab: normalise the nested-include comparison and export SplitComponentPath (81322b0)
  • platform: drop the sync ResolveRunConfig wrapper the deadcode gate rejects (9f2bb87)
  • platform: push effective_config as the flat per-provider controls map (fd04954)

👷 CI/CD

  • release: pin v0.4.49 refs [skip ci] (0c96d72)

0.4.49 (2026-08-31)

🐛 Bug Fixes

  • ci: treat a review that completes without structured output as zero findings (fb00f18)

✅ Tests

... (truncated)

Commits
  • bede38d chore(release): 0.4.44 [skip ci]
  • 0217d76 fix(controls): address review on the security policy source control
  • 1eaca39 docs(controls): update controls doc to make it more precise
  • 9d62204 feat(controls): add projectMustHaveSecurityPolicySource (ISSUE-601, GitLab Ul...
  • cfb0484 ci(release): pin v0.4.43 refs [skip ci]
  • 7098777 chore(release): 0.4.43 [skip ci]
  • a70ef57 fix(controls): address review on the MR approval/settings controls
  • 6345dc4 feat(controls): add mergeRequestSettingsMustBeCompliant (ISSUE-506) with a co...
  • deacbfb feat(controls): make ISSUE-503 approval-settings findings read as current-vs-...
  • 4d247c2 ci(release): pin v0.4.42 refs [skip ci]
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [getplumber/plumber](https://github.com/getplumber/plumber) from 0.4.39 to 0.4.44.
- [Release notes](https://github.com/getplumber/plumber/releases)
- [Changelog](https://github.com/getplumber/plumber/blob/main/CHANGELOG.md)
- [Commits](getplumber/plumber@031bc86...bede38d)

---
updated-dependencies:
- dependency-name: getplumber/plumber
  dependency-version: 0.4.44
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file gha no-jira labels Sep 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 2, 2026 07:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file gha no-jira labels Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file gha no-jira

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants