Plumber Radar is a Software Supply Chain Security product by Plumber. Pricing is free.
Plumber Radar is a public scanning tool that analyzes CI/CD pipeline configurations of GitLab and GitHub projects for security misconfigurations. Users submit a public GitLab or GitHub repository URL, and the tool runs an automated analysis of the project's CI/CD workflows and pipelines. GitLab scans take approximately 5-10 minutes, while GitHub scans take approximately 1-3 minutes. The tool evaluates repositories against a defined set of security controls, including: - Workflow permissions declaration - Branch protection status - Pinning of third-party actions by commit SHA - Verification that actions come from authorized sources - Restoration of untrusted caches in release workflows - References to archived repositories - Use of "secrets: inherit" in reusable workflows - Execution of unverified scripts - Hardcoded jobs in pipelines - Use of forbidden container image tags - Ambiguous tag/branch references in actions - Known CVEs carried by actions Based on these checks, each scanned project receives a letter score (A through E) and a breakdown of issues by severity (Critical, High, Medium, Low). The Radar page displays a public dashboard of scanned open-source projects selected by star count, showing score, provider, last analyzed time, star count, and issue counts, with filtering options by provider (GitLab/GitHub), configuration type (default/custom), activity window, and inclusion of archived repositories or forks. Users can trigger analysis on additional repositories directly from the page.
Common questions about Plumber Radar including features, pricing, alternatives, and user reviews.
Plumber Radar is Scans public GitHub/GitLab repos for CI/CD pipeline security misconfigurations, developed by Plumber. It is a Application Security solution designed to help security teams with CI/CD, Supply Chain Security, Security Scanning.
Plumber Radar is built for security teams handling CI/CD, Supply Chain Security, Security Scanning, Misconfiguration. Teams typically adopt Plumber Radar when they need to application security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/plumber-radar
Plumber Radar is a free Application Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://getplumber.io/radar for download and installation instructions.
Popular alternatives to Plumber Radar include:
Compare all Plumber Radar alternatives at https://cybersectools.com/alternatives/plumber-radar
Plumber Radar is for security teams and organizations that need CI/CD, Supply Chain Security, Security Scanning, Misconfiguration, CVE. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Application Security tools can be found at https://cybersectools.com/categories/application-security
Head-to-head feature, pricing, and rating breakdowns.
Software supply chain security platform with SBOM, provenance, and vuln prioritization.