Issues
Issues list
Every issue is raised by a control and has a unique ISSUE-XXXX identifier. The control is named by the CTRL-nnn id the Platform’s Policies page shows; its fields and defaults live on the Controls configuration page.
Click any issue for its full description, impact, before/after configuration examples, and remediation steps. Pick a provider tab below, or All for every issue code once, whichever provider raises it.
The severity shown here is the issue’s own. In a report, a finding that is part of an attack path shows the path’s tier instead, and a finding on no path shows its own severity; every output keeps the issue’s own severity next to the contextual one as baseSeverity.
CI/CD provider
CI/CD Container Images
CI/CD Variables
Pipeline Composition
Access and Authorization
Open Source CLI only
GitHub Actions issues are reported by the Open Source CLI only. Plumber Platform does not scan GitHub Actions workflows yet.
CI/CD Container Images
CI/CD Variables
CI/CD Secrets
Pipeline Composition
Access and Authorization
Third-party actions
Workflow triggers and permissions
CI/CD Container Images
CI/CD Variables
CI/CD Secrets
Pipeline Composition
Access and Authorization
Third-party actions
Workflow triggers and permissions
Issues status
In the Plumber Platform, an issue carries one of four statuses:
- Detected: the default state of a newly discovered issue.
- In progress: somebody started working on the fix.
- Dismissed: somebody assessed the issue and set it aside. A dismissed issue stays ignored when a later analysis detects it again.
- Fixed: the issue is fixed, or no longer detected. Reintroduced and detected again, it goes back to Detected.
The usual lifecycle: