
Open-source tool that scans, scores, and fixes CI/CD pipeline security issues

Open-source tool that scans, scores, and fixes CI/CD pipeline security issues
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Plumber is an open-source security tool focused on CI/CD pipeline security for GitLab and GitHub environments. The tool maps an organization's pipelines, detects security issues attackers commonly exploit, and assigns a letter grade (A to E), called the Plumber Score, to represent the security posture of a given CI/CD setup. The product identifies issues such as exposed secrets and unmasked variables, untrusted container registries, mutable image tags, unpinned or vulnerable third-party actions, dangerous triggers, over-broad permissions, and missing branch protection. Each finding includes a remediation guide. On the open-source command-line interface, fixes are advisory, providing step-by-step guidance. On the paid Platform offering, an AI agent applies fixes automatically and opens merge requests, with all agent actions checked against defined rules for auditability. Plumber operates a dual model: a free, open-source CLI for scanning individual pipelines, and a Platform product that monitors an entire organization continuously, offering dashboards, historical data, drift alerts, and AI-driven remediation. The Platform is free for up to 10 projects and paid tiers scale to unlimited projects with additional features such as unlimited history, portfolio views, and dedicated support. The company also runs Plumber Radar, a free initiative that continuously scans public GitLab and GitHub projects to score their CI/CD security, providing visibility into the state of CI/CD security across open-source projects. Plumber positions its offering as helping organizations meet software supply chain and CI/CD security requirements found in frameworks such as ISO 27001, NIS2, DORA, SOC 2, and the EU Cyber Resilience Act.