Skip to content

build(deps): bump getplumber/plumber from 0.4.63 to 0.5.1 in the actions group - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-05918fef99
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-05918fef99

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: getplumber/plumber.

Updates getplumber/plumber from 0.4.63 to 0.5.1

Release notes

Sourced from getplumber/plumber's releases.

v0.5.1

0.5.1 (2026-09-17)

🐛 Bug Fixes

  • component: run the plumber job on branch pipelines with an open MR and on plumber/ branches (045fe6f), closes #476

📚 Documentation

👷 CI/CD

  • release: pin v0.5.0 refs [skip ci] (1472696)

v0.5.0

0.5.0 (2026-09-17)

⚠ BREAKING CHANGES

  • identity: every ISSUE-406 and ISSUE-409 finding re-keys; a dismissal made under recipe version 4 no longer suppresses them and the platform re-detects the issue once.

Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01FUFtr3m8zC2mVNKVTQvaNz

✨ Features

  • identity: recipe version 5, the override fingerprint keys ISSUE-406 and ISSUE-409 (38c87b0)
  • ir: fingerprint an include's override content from the overridden keys and their values (a8378a5)
  • policies: overridden findings carry the override fingerprint and the overridden jobs (e133aba)

🐛 Bug Fixes

  • ir: the override fingerprint hashes the whole local job block, nested keys included (12fac4c)

👷 CI/CD

  • release: pin v0.4.63 refs [skip ci] (9c6f60d)
Changelog

Sourced from getplumber/plumber's changelog.

0.5.3 (2026-09-19)

🐛 Bug Fixes

  • gitlab: a required template matches its identity from the ref, not only its file path (056e7c8)
  • gitlab: a versioned template include keeps its template identity when the tag listing fails (724aa10)
  • platform: a linked run never calls GitLab for an include the platform served without its observation (d990b31)
  • platform: a version fact the platform did not serve reads as platform_observation_missing, not as a failed probe (52e1c47)

👷 CI/CD

  • release: pin v0.5.2 refs [skip ci] (cd7ef86)

0.5.2 (2026-09-18)

✨ Features

  • identity: recipe version 6, one identity per rule for ISSUE-405, ISSUE-408 and ISSUE-417 (b4f43ed)
  • policies: one finding per rule for missing required templates, components and actions (row 107) (50f6cf7)

👷 CI/CD

  • release: pin v0.5.1 refs [skip ci] (0648860)

0.5.1 (2026-09-17)

🐛 Bug Fixes

  • component: run the plumber job on branch pipelines with an open MR and on plumber/ branches (045fe6f), closes #476

📚 Documentation

👷 CI/CD

  • release: pin v0.5.0 refs [skip ci] (1472696)

0.5.0 (2026-09-17)

⚠ BREAKING CHANGES

... (truncated)

Commits
  • 3828988 chore(release): 0.5.1 [skip ci]
  • c083e0a docs(component): list when the plumber job runs and the workflow rule that av...
  • 045fe6f fix(component): run the plumber job on branch pipelines with an open MR and o...
  • 1472696 ci(release): pin v0.5.0 refs [skip ci]
  • c0b4d0f chore(release): 0.5.0 [skip ci]
  • 12fac4c fix(ir): the override fingerprint hashes the whole local job block, nested ke...
  • 38c87b0 feat(identity)!: recipe version 5, the override fingerprint keys ISSUE-406 an...
  • e133aba feat(policies): overridden findings carry the override fingerprint and the ov...
  • a8378a5 feat(ir): fingerprint an include's override content from the overridden keys ...
  • 9c6f60d ci(release): pin v0.4.63 refs [skip ci]
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [getplumber/plumber](https://github.com/getplumber/plumber).


Updates `getplumber/plumber` from 0.4.63 to 0.5.1
- [Release notes](https://github.com/getplumber/plumber/releases)
- [Changelog](https://github.com/getplumber/plumber/blob/main/CHANGELOG.md)
- [Commits](getplumber/plumber@10837e4...3828988)

---
updated-dependencies:
- dependency-name: getplumber/plumber
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Asuniia as a code owner September 20, 2026 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants